Re: Last Call: <draft-ietf-httpbis-http2-16.txt> (Hypertext Transfer Protocol version 2) to Proposed Standard

Dave Cridland <dave@cridland.net> Wed, 07 January 2015 13:07 UTC

Return-Path: <dave@cridland.net>
X-Original-To: ietf@ietfa.amsl.com
Delivered-To: ietf@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id A8CA61A8A4E for <ietf@ietfa.amsl.com>; Wed, 7 Jan 2015 05:07:57 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.378
X-Spam-Level:
X-Spam-Status: No, score=-1.378 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FM_FORGED_GMAIL=0.622, HTML_MESSAGE=0.001, SPF_PASS=-0.001] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id OyKBxjFOP3yf for <ietf@ietfa.amsl.com>; Wed, 7 Jan 2015 05:07:55 -0800 (PST)
Received: from mail-ob0-x233.google.com (mail-ob0-x233.google.com [IPv6:2607:f8b0:4003:c01::233]) (using TLSv1 with cipher ECDHE-RSA-RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id C94581A8A15 for <ietf@ietf.org>; Wed, 7 Jan 2015 05:07:55 -0800 (PST)
Received: by mail-ob0-f179.google.com with SMTP id va2so2923280obc.10 for <ietf@ietf.org>; Wed, 07 Jan 2015 05:07:55 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cridland.net; s=google; h=mime-version:in-reply-to:references:date:message-id:subject:from:to :cc:content-type; bh=rzn6nGu9czseEucEgmPqi5Cl5YjCk0FFlPdzG+1P94s=; b=E0hjmRk8YM+jQkeYCp5OYCti9O7wb/MxD2M6drT54UhYw7cPFgv7SIIsk0IU5Yrh+o FWZbo4woVD9b0g/BU27loFCER7m4jCxA3T1ZEqeWPufp04MmoE//HZJpCQhNUb+zRPeB GXOslQIQ9q7NWme8hrM/gNEeGJCfemK27VTd8=
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=x-gm-message-state:mime-version:in-reply-to:references:date :message-id:subject:from:to:cc:content-type; bh=rzn6nGu9czseEucEgmPqi5Cl5YjCk0FFlPdzG+1P94s=; b=FkoSF03/qGUZH7CqyrW95elM3LEja9g7bQr+u/YCFXtBUqqUtNXH/6c6bLQkjqzcGl M5yVwA1j6ACLt3dBtL4zL/DrM03y2TDEb+a13hvCpWazr687b7t99d59J+sR8//jw8VX ebB1ApsajS4ZmRPP2P00sXibtUCTuTiwQnoI9AnIBHqy0hVuRTMvoDVLF1whTAIZe4Pb P7+4nbloLNIjiHPKN9ZD9dVj5wAF3ret8jPxWaVO7iImn0nxhQKAWGTyZMvYBVC/GvgH 0Vcg+j+bLRSMLdKZ9Igy194Ckx4IZOEyVFteASMcb6fXNS1ZU1esRgtGqqTfJp1l/CvP tRlA==
X-Gm-Message-State: ALoCoQnaaR0RwrOEM5uYnojtEizzezdCpue4YQ1sKx5GYTKYtMoZpg6aGEhbcz3WrYnaL2KbSnNk
MIME-Version: 1.0
X-Received: by 10.202.212.210 with SMTP id l201mr1714735oig.117.1420636074956; Wed, 07 Jan 2015 05:07:54 -0800 (PST)
Received: by 10.60.84.171 with HTTP; Wed, 7 Jan 2015 05:07:54 -0800 (PST)
In-Reply-To: <54A81E9A.1020700@cisco.com>
References: <CAK3LatFh3ZU8ACk8grzLA9oCv2qqUHttz2z83b66xKnfs78mRA@mail.gmail.com> <54A7DBFC.8010800@cisco.com> <20150103143226.GC13599@besserwisser.org> <89DB2965-68B1-43D0-BBEB-FF49DB666A6D@frobbit.se> <54A81E9A.1020700@cisco.com>
Date: Wed, 07 Jan 2015 13:07:54 +0000
Message-ID: <CAKHUCzx36nBfXnVC3jeBAJijRTyf4ju_MvBn4XcL48Kre6ef+Q@mail.gmail.com>
Subject: Re: Last Call: <draft-ietf-httpbis-http2-16.txt> (Hypertext Transfer Protocol version 2) to Proposed Standard
From: Dave Cridland <dave@cridland.net>
To: Eliot Lear <lear@cisco.com>
Content-Type: multipart/alternative; boundary="001a113d2da09a72b3050c0f9cef"
Archived-At: http://mailarchive.ietf.org/arch/msg/ietf/V44TCoKM9Hrr8iu8QhlpHk2uJVs
Cc: Delan Azabani <delan@azabani.com>, Måns Nilsson <mansaxel@besserwisser.org>, "ietf@ietf.org Discussion" <ietf@ietf.org>, Patrik Fältström <paf@frobbit.se>
X-BeenThere: ietf@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: IETF-Discussion <ietf.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ietf>, <mailto:ietf-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ietf/>
List-Post: <mailto:ietf@ietf.org>
List-Help: <mailto:ietf-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ietf>, <mailto:ietf-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 07 Jan 2015 13:07:58 -0000

On 3 January 2015 at 16:53, Eliot Lear <lear@cisco.com> wrote:

> Finally, to address Måns' comments, additional data for the target
> doesn't get signed (but correct me if I missed a change).  (Actually,
>

I'm confused by this comment. You're saying (or you appear to be saying)
that use of SRV would place greater emphasis on DNSSEC, but additional
records don't get signed, and therefore the address record wouldn't be
signed in this case.

I'm not clear on where the requirement for DNSSEC comes into this, but
given that without SRV (and without DNSSEC that is no longer required),
there would be no signature on the address record anyway, I'm not sure it
matters.

I would in any case strongly support addition of SRV into HTTP/2 URI
resolution, and furthermore, I would strongly support additional work on
DNS (and DNSSEC) to address any performance or security issues at that
level.

As a final comment, I would note that if "IANA policy" is causing us
problems, we should just change it - these are technically speaking not
IANA's policies but ours.

Dave.