Re: [IPsec] Robert Wilton's Discuss on draft-ietf-ipsecme-add-ike-11: (with DISCUSS and COMMENT)

mohamed.boucadair@orange.com Thu, 27 April 2023 09:48 UTC

Return-Path: <mohamed.boucadair@orange.com>
X-Original-To: ipsec@ietfa.amsl.com
Delivered-To: ipsec@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id EE622C1522AB; Thu, 27 Apr 2023 02:48:27 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.797
X-Spam-Level:
X-Spam-Status: No, score=-2.797 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_MSPIKE_H2=-0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, UNPARSEABLE_RELAY=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=orange.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id mhq5DFzKnd9w; Thu, 27 Apr 2023 02:48:24 -0700 (PDT)
Received: from relais-inet.orange.com (relais-inet.orange.com [80.12.66.41]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id CC4CCC15153C; Thu, 27 Apr 2023 02:48:23 -0700 (PDT)
Received: from opfedar05.francetelecom.fr (unknown [xx.xx.xx.7]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits)) (No client certificate requested) by opfedar20.francetelecom.fr (ESMTP service) with ESMTPS id 4Q6WBs5mVlz8tM7; Thu, 27 Apr 2023 11:48:21 +0200 (CEST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=orange.com; s=ORANGE001; t=1682588901; bh=EcSb6VxdQ3cg0xzPy/PJAU44V2dupxnvl+ufUYWPjJE=; h=From:To:Subject:Date:Message-ID:Content-Type: Content-Transfer-Encoding:MIME-Version; b=YxyK+7XX+eotC7CTrVkXxZOG4jnL0nHXOPrTA6UjzDf5ZAUlwfkk6g3pZlXHfNB1z 13suepffJwMiJSjKZng/+EC5iMi+bS7jLB+Eb+q2MJejZmIs5ZDsW1iGZPBINO6q7k ZmgohSJfmApHMFifs9S4PgWR3VJvSHTDqcSYjHt6ZHCOV5rl0TGRrmQNks1mgeupCE nC9o06XSyWWdzQf0JGKrMxlyy/S1t44l5VJH1zBCCEz5YPbfEAnJaDCjiA39NBbzLe 0on3R9H0V3Ijrgxi03CDVS6jRgTOuaFenG5aDIZpsadt+9Oy7WLfq1AW3L6I9yw68N cyj52Riq+htXg==
X-TM-AS-ERS: 10.107.176.74-127.5.254.253
X-TM-AS-SMTP: 1.0 b3BmZWRhbTMzLmZyYW5jZXRlbGVjb20uZnI= bW9oYW1lZC5ib3VjYWRha XJAb3JhbmdlLmNvbQ==
X-DDEI-TLS-USAGE: Used
Received: from opfedam33.francetelecom.fr (unknown [xx.xx.xx.74]) by opzinddimail4.si.francetelecom.fr (Postfix) with ESMTPS; Thu, 27 Apr 2023 11:48:21 +0200 (CEST)
Received: from EUR04-DB3-obe.outbound.protection.outlook.com (mail-db3eur04lp2056.outbound.protection.outlook.com [104.47.12.56]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by relais-m365.orange.com (ESMTP service) with ESMTPS id 4Q6WBs0qcfz8sXj; Thu, 27 Apr 2023 11:48:21 +0200 (CEST)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=YSeyP4pHUDrmMlEwnblntPMt/4frmYBgSUwkFMlgWLdP7/5Q71pxT0Rm6WLWNn3/bWiRYwZzJ7WDmrhVqpSSy+Er1apI6pP3K0BuPl6qQLXM77Z7/fyv6bR8Qsiy9BBf+fxh+69Nup0QRQkNEB6I46BWT0KymmVWf7hbGJ7dYImp/wjxBVH57uss9tCUT/xMy4Z2igNAL8VbAJ80Pizu0iSyuOxC1akjloBTbcttSisY0K0Gr4rC99OgvGJkUwrbLBCEGE6i4vwyz92MsSzTRMzEoHWEckmqy6kRTGhGdMuvshWgK7AcOo66280S09gdHj6V8YJUQeXCPvUWmz+h/g==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=u1Jxe1sAeI32ROES0r80/dkZeaggdmSPstwvTmnVDuc=; b=oJSSekkht2lkTeP90bQZNJli/vnOW3dlGMcjE5n0sMSlE5yBFOS32t9LtsgMJdoD9nUNig3pzzN9SwZ2dKc2RtIMv1k3nXSz7PT32vvg42Z4hNMgTrBoHyLnBdRLVvvyQeS1L15uqi0gE6sw2tMc9q57FAcSVQ1rvhRFNa/ysFqh9ESV8AYcD4O3vzX9JV8D4+ksI3M33QQLz7maR2C702lXzAIS4mlXPOhzdy10SGkISL0+g3I/OFjggg0xxusyJcQNxR0phuq+DSb9CiPN4E0pgGxnFYBmURi/Lk7uAMjVHrR8vHKNxf65JU4onVMgEGblO7waFkvnesaIlW8yAg==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=orange.com; dmarc=pass action=none header.from=orange.com; dkim=pass header.d=orange.com; arc=none
Received: from PAVPR02MB9673.eurprd02.prod.outlook.com (2603:10a6:102:319::5) by AS4PR02MB8309.eurprd02.prod.outlook.com (2603:10a6:20b:510::19) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.6340.21; Thu, 27 Apr 2023 09:48:19 +0000
Received: from PAVPR02MB9673.eurprd02.prod.outlook.com ([fe80::dcd6:6396:fe64:e7bc]) by PAVPR02MB9673.eurprd02.prod.outlook.com ([fe80::dcd6:6396:fe64:e7bc%7]) with mapi id 15.20.6340.022; Thu, 27 Apr 2023 09:48:19 +0000
From: mohamed.boucadair@orange.com
To: Robert Wilton <rwilton@cisco.com>, The IESG <iesg@ietf.org>
CC: "draft-ietf-ipsecme-add-ike@ietf.org" <draft-ietf-ipsecme-add-ike@ietf.org>, "ipsecme-chairs@ietf.org" <ipsecme-chairs@ietf.org>, "ipsec@ietf.org" <ipsec@ietf.org>, "kivinen@iki.fi" <kivinen@iki.fi>
Thread-Topic: Robert Wilton's Discuss on draft-ietf-ipsecme-add-ike-11: (with DISCUSS and COMMENT)
Thread-Index: AQHZeOlhTYHMHcjr+E+1YQKuNB8Zdq8+5Iaw
Content-Class:
Date: Thu, 27 Apr 2023 09:48:19 +0000
Message-ID: <58988_1682588901_644A44E5_58988_382_1_PAVPR02MB9673870C49FBAA1EDA6A514A886A9@PAVPR02MB9673.eurprd02.prod.outlook.com>
References: <168258716961.30194.4411331064355666357@ietfa.amsl.com>
In-Reply-To: <168258716961.30194.4411331064355666357@ietfa.amsl.com>
Accept-Language: fr-FR, en-US
Content-Language: fr-FR
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
msip_labels: MSIP_Label_f47c794b-e3ab-43f0-9e0f-29fc3e503192_Enabled=true; MSIP_Label_f47c794b-e3ab-43f0-9e0f-29fc3e503192_SetDate=2023-04-27T09:48:17Z; MSIP_Label_f47c794b-e3ab-43f0-9e0f-29fc3e503192_Method=Standard; MSIP_Label_f47c794b-e3ab-43f0-9e0f-29fc3e503192_Name=Orange_restricted_external.2; MSIP_Label_f47c794b-e3ab-43f0-9e0f-29fc3e503192_SiteId=90c7a20a-f34b-40bf-bc48-b9253b6f5d20; MSIP_Label_f47c794b-e3ab-43f0-9e0f-29fc3e503192_ActionId=3977101b-bcd1-42ba-9096-7abc73ce86c2; MSIP_Label_f47c794b-e3ab-43f0-9e0f-29fc3e503192_ContentBits=2
authentication-results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=orange.com;
x-ms-publictraffictype: Email
x-ms-traffictypediagnostic: PAVPR02MB9673:EE_|AS4PR02MB8309:EE_
x-ms-office365-filtering-correlation-id: 29343151-a30e-4310-c976-08db4704884c
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: YpbKnjC4RnXSp3dYqDDO14Uq4vk4eoyIbWxZQJksu4ijoDQQHs/6Qwln4nl20O5RcPg98NzNuIGPMDHxVRutRwvwIZjSXp6MfTgjOQKRQiHrehPZtcVP28D+pqsGV6WI92bc0EEdof9bAEjTSB+rwhzbmU+ZSZ48jMJcXXVAIr30W475t3ohsNsaeFwv/w+i/BGhmYDy3JdqtTKXFqs3pbysHn9yFzUhg/nyL+eFx9XZHK+QQCwDaF1UzXVcoNuymu2LxlvM7JYw11dVRG8F2j3Ym5LFhZ5+tr1EtBfUcQmBgj+KzUyzbrlqvXtLOhe/MDpWh97GRNAE/MXWmAcX5PvzCVJyUCerYaKZpQSmkRQwJOAa5rq+7Ewr+2fLq2eWLS3u2fq/wRnBqNTmcea1KtqinYXVGaKjUAYwtyAyRU2qXAajQCGGH2xDUfoD4y7cFbxK8JQoKzpMvKKJ8cbqVFFQcEu+4Ek17HcVzg3irM+6dsuYHjBSey+xCWYus/00oLvYduz7DD1tlyDs6fieXSLPkynfbKyEg+Ovv3NHKMOt+XFpxKHAH0lODTMwVppAJt3UrG49tOK/dlSDBI4LOsCQRSmvQcJsVEo2BoBjrPjuuxP1f2/XPSydHQUUMsEO
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:PAVPR02MB9673.eurprd02.prod.outlook.com; PTR:; CAT:NONE; SFS:(13230028)(4636009)(366004)(346002)(39860400002)(136003)(396003)(376002)(451199021)(4326008)(76116006)(66946007)(66556008)(52536014)(66446008)(5660300002)(66476007)(7696005)(316002)(9686003)(64756008)(41300700001)(2906002)(8676002)(8936002)(54906003)(110136005)(86362001)(38070700005)(478600001)(122000001)(38100700002)(71200400001)(33656002)(83380400001)(55016003)(66574015)(6506007)(26005)(186003); DIR:OUT; SFP:1102;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: VyyWyUdnJ4V4iFaUl2bCU/JSoz8IEUURO+gKpvgNJWAmkzDaCF7dBlQumhRoD6+8cVK6udUGG57MRB55z8SWVhiDYpNIu5Bl5VCliHJJ24Pw5KTJ00ltlFTWaeRQuy6/jYH2TXrB/nzsfeP1ZVNc4Lv3W9DkOabc5g60e6y3CU1PWet2ga0wc7oh1FGuigb427/ySWKLD1wepXanHulLdvUVxcx0q6IxSH517d9dLFftGGr/xIH/VZQs/X6r5N9E4fil5MXd0yqj3VXMz0KmTsI7iDAupJXWTaHnJBJBOKVvPCARDKiSGx8/I/sB1avL6f1fUl9B2t9VAQI96YAbW17ArX3YDoQlI3Rxv9axhV2Ay81Td4okG44aebWip0aV8IGdCKFLQO/MF2/pPcdtHCbJUDHmV3AW8fZzk6YY/ToEM1RDCX5ySiF3k4REXWCCXV75u49oZKYAhU07dv5Ia1D8a9ZH9WiINHocQn+ANCW7wevHhqRDLw+RVlW3pJfroyb3yVtILYehNY/KdZH1kG8JE2dTDhshzHB5tYQpyH8khqVBvxdNqEtE3b+5bh/SJCzxrhG7ZyOv4zI6dtE2vvOz7t0Yxb2VAYgaeRXcu+ocGnf2Tf9FRAjvEviK95LIqwRMgibbX3jkNqcjaDTkxhr0IfRcXtZ2zKbFH6LC+4DIAopR9rI9Ol/rhtY3XyRXsKaiSjc3/dmoFmR5SMF8ey6MJ73izTrEoWrtjE+BLoRNPbUpf109wkz21240PO7rT3jovyL5+qT26P3JAOF7K8EdOo68OnrJJm5cIF7XU7gDJ8ZYI5mU+0vDR4pME9LLnVS6m/U9S3lWeRfP58e0v0vjCKNHzy8SBGVHGBaZrArE97AQK83pVUW7meJpHS16yWvdcYZqi/VwSe7c94sS9NgZiR6CqCDmBwe42N4POGtfHVjJKnt44LAYmF8saSChb0bFJ8nqVldIKt2N0S0t02Nkx6rSScfH0eHECZ1eBVJpz/wOS30uH160KcDOggGiSfSgZERokh8IR4vEX4FBZ1Cxs522b4O2UVbWj/T6NdOcaeXEcqupvXIl1mYBdnzZu7X6I9b8UHi+b/8IIgFucYea210AvHGPU1CHpqLQ69yJm6NRypPAXlzJIfqev77okEuczbRKbckEBp3YOTJ4xyWE4X3SekEiG4nDAHn8GcIlJKr1k8ChKdw3sVd6lVeMn6NnP8kq8JSaPInU/pkDFXEjVeHyOoBLJtnpmRPfUodZjbJJZej0aLufClJL4L9+9e5LNVLk/P+JGQGkHs30kU78HfT0oBFr2jndqN4TQKiE4sNHD4PagKUDYvBwI3GJpjxaVRNwbApeMTEKlWP40R9FppxqOJBm7i0//4sO2RNFS/+NLTL2HbqpQ1kqqwvqiXZF+n7L2QVYVgbf9YkXd1naRq2VmnU8xcicKX8dC2IfJmo9r/saAcQJaQsLldhYdEOe31ASekU8RTFImEfcliIAMxApks1x/7tyMj3+kPI3SYT7shWzBE3E6muB/QzyhNwTTF7KREhMlmaRuk5CwvuLO8M7BAdsMOaLrfweTrv8V8RcjL5WYwLTdrYTofiiYGmnOa0wwpZOTl4cTsBVWw==
Content-Type: text/plain; charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
X-OriginatorOrg: orange.com
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: PAVPR02MB9673.eurprd02.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: 29343151-a30e-4310-c976-08db4704884c
X-MS-Exchange-CrossTenant-originalarrivaltime: 27 Apr 2023 09:48:19.4745 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 90c7a20a-f34b-40bf-bc48-b9253b6f5d20
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: k/wa8V3NafAIw4u4ugYDBKViM5o3xq1flQaUpfzppFDb72G/lpVfcWvDojP9yJZ3cnDbeMK3ne4JF8+tufE88ynRaj7pjvwVE551XVuChfo=
X-MS-Exchange-Transport-CrossTenantHeadersStamped: AS4PR02MB8309
X-TM-AS-ERS: 10.107.176.74-127.5.254.253
X-TM-AS-SMTP: 1.0 b3BmZWRhbTMzLmZyYW5jZXRlbGVjb20uZnI= bW9oYW1lZC5ib3VjYWRha XJAb3JhbmdlLmNvbQ==
X-TMASE-Version: DDEI-5.1-9.0.1002-27590.006
X-TMASE-Result: 10--39.426700-10.000000
X-TMASE-MatchedRID: jFqw+1pFnMz/9O/B1c/Qy461Z+HJnvsOYi1nZ7WB6LEM74Nf6tTB9t9q V1RzMGoXrpyextBSI2t3ZVcbJy0H7hRLQnD6pjPPk4nP+tQi+rZ+G11aZ3USRKwBH1NnTw69DB8 FjIZjOlYvYRhsicUjm6qhhq9xqZ/8qcvngzkLMRDN+qWlu2ZxaFmlOOES95HRUekjLrC3lTBcVM ejXN5JLzLS2wF/9twDHBmPMhutr4sSdpeGjFPnfpd+vKkqem+eSuH+GfgmQGekS8ofY79gjKJv4 V2TxsYRTZNQaLpf+7j+ZyPCiB0OuVSeSaS62VbkX9knSHW8uXUpA2ExuipmWqaYkqKEtUB4QH/M 2Sdyvo3n22EcSrQBnQAXgr1m1OnKcCGg8P80DiSiVU7u7I4INedjQ/G9Lk6Q33Nl3elSfsp47RP WB5T7IXhRxBY+L5I9U9V+S7+BtgRXodxPGLVTctyBRU/cKn699v33UW8WNYBqrsOvUFEKy42ufh W+a8ofPhG3C4bJ9ueRaipMO5p3M2wC7mTEXmq9OIQ9GP2P2u8q+MsVDZ0mzEb+iRVnpz920BhZS jgdIiRfZPFUbFYJwabpKWlCJEtTUb9lEuZnMyTGSzOfy00X/xTv3LFQM9Ubwx+D6caAJK77mZcX lr4l+Yfg/53yPqyaEbq9aVy5FCnARMRsbdtWtWHki4hrFM75xWYmCT/s4UEu662t3R6oY3ILRW+ nYqsSQOrngCJ9iTN7Nj4X7Dg9vvI1MC3W6vL4r1G5Bi35epAqdsryWvacjoF1QgT+kYVuKDnLES Ylt3/OVXs+hRyHfxls40m1/h6LAlb6OR37f+7og9l0AIlL/n0tCKdnhB58uME6WhSqqOG+X1fgz IYv2AP5zT0d393c4kYXbobxJbLyU/oX+tpNmCG2Ull2Wedt
X-TMASE-SNAP-Result: 1.821001.0001-0-1-22:0,33:0,34:0-0
X-TMASE-INERTIA: 0-0;;;;
X-TMASE-XGENCLOUD: d97d4bb7-0faf-49cb-9a2b-f91d4f11d9d4-0-0-200-0
Archived-At: <https://mailarchive.ietf.org/arch/msg/ipsec/TqFZ92LiUkGoZ-eFtibB749WBug>
Subject: Re: [IPsec] Robert Wilton's Discuss on draft-ietf-ipsecme-add-ike-11: (with DISCUSS and COMMENT)
X-BeenThere: ipsec@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: Discussion of IPsec protocols <ipsec.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ipsec>, <mailto:ipsec-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ipsec/>
List-Post: <mailto:ipsec@ietf.org>
List-Help: <mailto:ipsec-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ipsec>, <mailto:ipsec-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 27 Apr 2023 09:48:28 -0000

Hi Rob, 

Thanks for the review. 

Please see inline. 

Cheers,
Med


Orange Restricted

> -----Message d'origine-----
> De : Robert Wilton via Datatracker <noreply@ietf.org>
> Envoyé : jeudi 27 avril 2023 11:19
> À : The IESG <iesg@ietf.org>
> Cc : draft-ietf-ipsecme-add-ike@ietf.org; ipsecme-chairs@ietf.org;
> ipsec@ietf.org; kivinen@iki.fi; kivinen@iki.fi
> Objet : Robert Wilton's Discuss on draft-ietf-ipsecme-add-ike-11:
> (with DISCUSS and COMMENT)
> 
> Robert Wilton has entered the following ballot position for
> draft-ietf-ipsecme-add-ike-11: Discuss
> 
> When responding, please keep the subject line intact and reply to
> all email addresses included in the To and CC lines. (Feel free to
> cut this introductory paragraph, however.)
> 
> ------------------------------------------------------------------
> ----
> DISCUSS:
> ------------------------------------------------------------------
> ----
> 
> Hi,
> 
> Thanks for this document.
> 
> This should be a trivial discuss to resolve, and only flagging it
> as a discuss
> because I think that it makes the spec unclear (or wrong):
> 
> (1) p 4, sec 3.1.  ENCDNS_IP* Configuration Payload Attributes
> 
>    *  IP Address(es) (variable) - Includes one or more IP
> addresses that
>       can be used to reach the encrypted DNS resolver identified
> by the
>       Authentication Domain Name.  For ENCDNS_IP4 this field
> contains
>       one or more 4-octet IPv4 addresses, and for ENCDNS_IP6 this
> field
>       contains one or more 16-octet IPv6 addresses.
> 
> Shouldn't this be zero or more IP addresses?  Otherwise, the
> example that only
> contains a domain and no IP address appears to be invalid.
> 

[Med] That text is correct. The field is present only when there is an IP address to convey; otherwise the field is skipped. The presence is indicated by this field: 

Num Addresses (1 octet) - Indicates the number of enclosed IPv4 (for ENCDNS_IP4) or IPv6 (for ENCDNS_IP6) addresses. 

> 
> ------------------------------------------------------------------
> ----
> COMMENT:
> ------------------------------------------------------------------
> ----
> 
> Minor level comments:
> 
> (2) p 0, sec
> 
>    This document specifies new Internet Key Exchange Protocol
> Version 2
>    (IKEv2) Configuration Payload Attribute Types to assign DNS
> resolvers
>    that support encrypted DNS protocols, such as DNS-over-HTTPS
> (DoH),
>    DNS-over-TLS (DoT), and DNS-over-QUIC (DoQ).
> 
> Are there any updates needed to RFC 9061 needed to cover
> manageability
> aspects/updates of the attributes defined in this draft?  Note,
> I'm not
> requesting that they be added to this draft, but instead, I want
> to check if
> there is any need or plan to address them.

Med: Not AFAIK.


> 
> (3) p 2, sec 2.  Terminology
> 
>    Do53:  refers to unencrypted DNS.
> 
> This term only turns up a few (3 times) in this doc, and its not
> clear to me
> that it improves its readability.  I didn't know what it meant,
> possibly just
> referencing to "Unencrypted DNS" would be better for the wider
> audience?
> 

[Med] Do53 is widely used but without a reference. I prefer to maintain in this section. Thanks.  

> (4) p 3, sec 3.1.  ENCDNS_IP* Configuration Payload Attributes
> 
>       -  0 if the Configuration payload has types CFG_REQUEST (if
> no
>          specific DNS resolver is requested) or CFG_ACK.  If the
>          'Length' field is set to 0, then later fields shown in
> Figure 1
>          are not present.
> 
> I found this text unclear & confusing when combined with the
> following two
> paragraphs.  I would suggest rewording the first sentence to
> something like:
> 
>    0, if the Configuration payload has (i) type CFG_REQUEST and no
>    specific DNS resolver is requested or (ii) type CFG_ACK.
> 

[Med] OK. 


> (5) p 13, sec Appendix A.  Sample Deployment Scenarios
> 
> Readability may be slightly improved by adding a sentence here to
> explain what
> the purpose of this section is.

[Med] We have a sentence in the intro:

   Sample use cases are described in Appendix A.  The Configuration
   Payload Attribute Types defined in this document are not specific to
   these deployments, but can also be used in other deployment contexts.
   It is out of the scope of this document to provide a comprehensive
   list of deployment contexts.

Will see if we can make a change.

> 
> (6) p 14, sec Appendix A.  Sample Deployment Scenarios
> 
>    Enterprise networks are susceptible to internal and external
> attacks.
>    To minimize that risk all enterprise traffic is encrypted
>    (Section 2.1 of [I-D.arkko-farrell-arch-model-t]).
> 
> Would "SHOULD be encrypted" be better than "is encrypted"? Or,
> alternatively,
> "Encrypting all internal enterprise traffic minimizes the risks of
> attacks
> (Section 2.1 of [I-D.arkko-farrell-arch-model-t]).
> 

[Med] We removed that sentence as per a comment from Paul.


> (7) p 14, sec Appendix B.  Examples
> 
> I would suggest putting each of the two examples into its own
> subsection.
> 

[Med] OK.

> Nit level comments:
> 
> (8) p 4, sec 3.1.  ENCDNS_IP* Configuration Payload Attributes
> 
>       -  0 if the Configuration payload has types CFG_REQUEST (if
> no
>          specific DNS resolver is requested) or CFG_ACK.  If the
>          'Length' field is set to 0, then later fields shown in
> Figure 1
>          are not present.
>       -  (4 + Length of the ADN + N * 4 + Length of SvcParams) for
>          ENCDNS_IP4 attributes if the Configuration payload has
> types
>          CFG_REQUEST or CFG_REPLY or CFG_SET; N being the number
> of
>          included IPv4 addresses ('Num addresses').
> 
> Possibly "(4 + 'Length of the ADN' + (N * 4) + Length of
> SvcParams)", and
> similarly for IPv6, would be more explicit.
> 

[Med] OK

> (9) p 5, sec 3.2.  ENCDNS_DIGEST_INFO Configuration Payload
> Attribute
> 
>    *  Length (2 octets, unsigned integer) - Length of the enclosed
> data
>       in octets.  This field MUST be set to "2 + 2 * number of
> included
>       hash algorithm identifiers".
> 
> For clarity, I suggest: "2 + (2 * 'number of included
>       hash algorithm identifiers')"
> 

[Med] OK

> (10) p 6, sec 3.2.  ENCDNS_DIGEST_INFO Configuration Payload
> Attribute
> 
>    *  Length (2 octets, unsigned integer) - Length of the enclosed
> data
>       in octets.  This field MUST be set to "2 + 2 * number of
> included
>       hash algorithm identifiers".
>    *  Num Hash Algs (1 octet) - Indicates the number of included
> hash
>       algorithm identifiers.  This field MUST be set to "(Length -
>       2)/2".
> 
> I suggest, included 'hash algorithm identifiers'.
> 

[Med] OK

> Regards,
> Rob
> 
> 

_________________________________________________________________________________________________________________________

Ce message et ses pieces jointes peuvent contenir des informations confidentielles ou privilegiees et ne doivent donc
pas etre diffuses, exploites ou copies sans autorisation. Si vous avez recu ce message par erreur, veuillez le signaler
a l'expediteur et le detruire ainsi que les pieces jointes. Les messages electroniques etant susceptibles d'alteration,
Orange decline toute responsabilite si ce message a ete altere, deforme ou falsifie. Merci.

This message and its attachments may contain confidential or privileged information that may be protected by law;
they should not be distributed, used or copied without authorisation.
If you have received this email in error, please notify the sender and delete this message and its attachments.
As emails may be altered, Orange is not liable for messages that have been modified, changed or falsified.
Thank you.