Re: [dnsext] draft-mohan-dns-query-xml-00.txt

Paul Wouters <paul@xelerance.com> Sat, 01 October 2011 17:30 UTC

Return-Path: <dnsext-bounces@ietf.org>
X-Original-To: namedroppers-archive-gleetwall6@lists.ietf.org
Delivered-To: ietfarch-namedroppers-archive-gleetwall6@ietfa.amsl.com
Received: from ietfa.amsl.com (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 0D65821F8FB0; Sat, 1 Oct 2011 10:30:46 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1317490246; bh=gZ1tDNNA5/sUfHfkLdWkgDeFtadhM4uHksZT0vj91aQ=; h=Date:From:To:In-Reply-To:Message-ID:References:MIME-Version:Cc: Subject:List-Id:List-Unsubscribe:List-Archive:List-Post:List-Help: List-Subscribe:Content-Transfer-Encoding:Content-Type:Sender; b=tXJriji+Q/YT4zRQpyvTnmfN17lbRi6z/5nlIr1IkBVFlFaKZ2+u/YVCC19DA0KvN PnaHJUSYlgwYfw654UYyZYzz6cj1GLYWHBSkb/CKQTh6wcE64S2FFviHWHz20EZnbM QTjMxsohSTkQUv8Yz02GewgiU7uPK1IK8JVNpP2w=
X-Original-To: dnsext@ietfa.amsl.com
Delivered-To: dnsext@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 4099121F8FB0 for <dnsext@ietfa.amsl.com>; Sat, 1 Oct 2011 10:30:45 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.444
X-Spam-Level:
X-Spam-Status: No, score=-4.444 tagged_above=-999 required=5 tests=[AWL=-1.845, BAYES_00=-2.599]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id RzFPFcMnduv5 for <dnsext@ietfa.amsl.com>; Sat, 1 Oct 2011 10:30:44 -0700 (PDT)
Received: from mx.xelerance.com (mx.xelerance.com [193.110.157.188]) by ietfa.amsl.com (Postfix) with ESMTP id 252BB21F8FA8 for <dnsext@ietf.org>; Sat, 1 Oct 2011 10:30:44 -0700 (PDT)
Received: from localhost (localhost [127.0.0.1]) by mx.xelerance.com (Postfix) with ESMTP id 4184463; Sat, 1 Oct 2011 13:33:37 -0400 (EDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=xelerance.com; h= content-type:content-type:mime-version:user-agent:references :message-id:in-reply-to:subject:subject:from:from:date:date :received:received:received:received; s=smtp; t=1317490416; x= 1318095216; bh=IEaNPLH06p/4VZUpGZyVOHO5z8Nem4MjiH0YxkQExsQ=; b=Z YTdeRbuy0jP+/qB0iUfiOtGZNN8BGDGaBkr7UNoc4L/OGcxhE7iVRTf+2nrXqer1 ONK9jlSftPwj7MvqPYgh6sUKUrSUDfhbmGE+Q+eZZMTtPGv2Nhou5dh5hU6xFJic X4MZe0jNFewtj1xzvsPYIY6PcwLhSBLqAiiToXvbwE=
Received: from mx.xelerance.com ([127.0.0.1]) by localhost (mx.xelerance.com [127.0.0.1]) (amavisd-new, port 10026) with LMTP id 8Q9bKPA0Gq4g; Sat, 1 Oct 2011 13:33:36 -0400 (EDT)
Received: from mail.xelerance.com (mail.xelerance.com [193.110.157.189]) (using TLSv1 with cipher ADH-AES256-SHA (256/256 bits)) (No client certificate requested) by mx.xelerance.com (Postfix) with ESMTPS id D5DEB2C; Sat, 1 Oct 2011 13:33:35 -0400 (EDT)
Received: by mail.xelerance.com (Postfix, from userid 1001) id B5F9D19DE; Sat, 1 Oct 2011 13:33:29 -0400 (EDT)
Received: from localhost (localhost [127.0.0.1]) by mail.xelerance.com (Postfix) with ESMTP id AFFBF19D9; Sat, 1 Oct 2011 13:33:29 -0400 (EDT)
Date: Sat, 1 Oct 2011 13:33:29 -0400 (EDT)
From: Paul Wouters <paul@xelerance.com>
To: Paul Vixie <vixie@isc.org>
In-Reply-To: <201110010458.26859.vixie@isc.org>
Message-ID: <alpine.DEB.2.00.1110011322430.20645@mail.xelerance.com>
References: <CACU5sDnBx5AijEgFXKNPjtcVdtBnBJamsn-f_ye0Jm3TQq0mvw@mail.gmail.com> <0394FB3B-6C2B-4D47-B1FA-AA54B7EB1053@kirei.se> <DDD7529C-9EF3-427F-AF90-2872CCD71ECF@cisco.com> <201110010458.26859.vixie@isc.org>
User-Agent: Alpine 2.00 (DEB 1167 2008-08-23)
MIME-Version: 1.0
Cc: dnsext@ietf.org
Subject: Re: [dnsext] draft-mohan-dns-query-xml-00.txt
X-BeenThere: dnsext@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: DNS Extensions working group discussion list <dnsext.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dnsext>, <mailto:dnsext-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/dnsext>
List-Post: <mailto:dnsext@ietf.org>
List-Help: <mailto:dnsext-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dnsext>, <mailto:dnsext-request@ietf.org?subject=subscribe>
Content-Transfer-Encoding: 7bit
Content-Type: text/plain; charset="us-ascii"; Format="flowed"
Sender: dnsext-bounces@ietf.org
Errors-To: dnsext-bounces@ietf.org

On Sat, 1 Oct 2011, Paul Vixie wrote:

> "plain old DNS wire format".  I truly do only expect this transport to be used
> when the normal UDP/53 and TCP/53 paths are middlebox-corrupted.

I am not sure people agree on the user cases for this.

If you truly think you are addressing the middlebox problem, most likely
you could just run the DNS over port 54 or 80/443.

This proposal does not at all address the problem where DNS is mangled due
to hotspot and captive portal scenarios. Once you work around that scenario,
for example like with the dnssec-trigger experiment that's still far from
workable to non-engineers, you usually get a clean connection with the
exception of port 53 mangling, which just moving to another port seems to
almost always fix it (with 80/443 having a slightly better chance then a
random port.

Doing DNS-over-HTTP is still going to get broken results in captive portals.

What dnssec-trigger is trying to do now is:
- selectable (but should be automatic) hot spot mode where you allow
   insecure dns only to go past captivity
- attempt to use DHCP assigned DNS servers as cache, validate locally
   - if broken, try and query auth servers directly
     - if broken, try an open resolver on port 80/443
       - if broken give user option for "insecure or cached only"

Aside from this, we have the new dnssec chains via alternative source,
both as a speedup and as a workaround using a leap of faith in TLS. this
is useful, though not a replacement for the above. It would also be nice
if any dnssec-chain extension would use some kind of standard so we can
feed it into a validating caching server.

Doing dns-over-http for broken middlewhere alone is going to be a partial
solution that is not going to be very useful on its own.

Paul

_______________________________________________
dnsext mailing list
dnsext@ietf.org
https://www.ietf.org/mailman/listinfo/dnsext