Re: [dnsext] draft-mohan-dns-query-xml-00.txt

Mohan Parthasarathy <suruti94@gmail.com> Wed, 28 September 2011 21:04 UTC

Return-Path: <dnsext-bounces@ietf.org>
X-Original-To: namedroppers-archive-gleetwall6@lists.ietf.org
Delivered-To: ietfarch-namedroppers-archive-gleetwall6@ietfa.amsl.com
Received: from ietfa.amsl.com (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 064AB1F0D27; Wed, 28 Sep 2011 14:04:24 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1317243864; bh=y6HBqz91cJVyp99z4L7YGfA179mzbmj1imW6RL9VbhY=; h=MIME-Version:In-Reply-To:References:Date:Message-ID:From:To:Cc: Subject:List-Id:List-Unsubscribe:List-Archive:List-Post:List-Help: List-Subscribe:Content-Type:Content-Transfer-Encoding:Sender; b=Y77ar6iraPAqAncHL2oTV3NNUt+BTyQTAU4O80+DV8XxdVupOWf/+3r6GhDPlnx1r 8vz0PluR7JlHAiYqKkaXEGzZaALVKsb7Ufy7A8EXuMOO5u0c52vknaP5dtDukJBNbi g+/vTjwoI/DAUXeZGmVMcWmCZdwPxHFX9qOlK9hQ=
X-Original-To: dnsext@ietfa.amsl.com
Delivered-To: dnsext@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 2FB7F1F0D27 for <dnsext@ietfa.amsl.com>; Wed, 28 Sep 2011 14:04:23 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -3.599
X-Spam-Level:
X-Spam-Status: No, score=-3.599 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, RCVD_IN_DNSWL_LOW=-1]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 0paDyu0cesTl for <dnsext@ietfa.amsl.com>; Wed, 28 Sep 2011 14:04:22 -0700 (PDT)
Received: from mail-yx0-f172.google.com (mail-yx0-f172.google.com [209.85.213.172]) by ietfa.amsl.com (Postfix) with ESMTP id 0DAA31F0D26 for <dnsext@ietf.org>; Wed, 28 Sep 2011 14:04:15 -0700 (PDT)
Received: by yxt33 with SMTP id 33so9925yxt.31 for <dnsext@ietf.org>; Wed, 28 Sep 2011 14:07:05 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=gamma; h=mime-version:in-reply-to:references:date:message-id:subject:from:to :cc:content-type; bh=W80QARPspCyI1ATCZKMozX7Bcggx0oXL6UD53WREfig=; b=bOq15/U2jLSIW80DDMvbsQjFAW4KsZStwrssNX7YQ/Gw8YJWB3fbTxTU6HL1ZtU2Zb jVUJ8uQZf+aPQzkDYzgo077IMXtiPIhGdgiSFW/dZsWXDwWrkWdRNHCFCYVJGGvxrn89 MMk+6uIJTr+MgBpkF/wbKRURSW1qtgllvDFrY=
MIME-Version: 1.0
Received: by 10.68.30.199 with SMTP id u7mr47223745pbh.55.1317244024886; Wed, 28 Sep 2011 14:07:04 -0700 (PDT)
Received: by 10.68.46.200 with HTTP; Wed, 28 Sep 2011 14:07:04 -0700 (PDT)
In-Reply-To: <alpine.LFD.1.10.1109281525430.25654@newtla.xelerance.com>
References: <CACU5sDnBx5AijEgFXKNPjtcVdtBnBJamsn-f_ye0Jm3TQq0mvw@mail.gmail.com> <alpine.LFD.1.10.1109281525430.25654@newtla.xelerance.com>
Date: Wed, 28 Sep 2011 14:07:04 -0700
Message-ID: <CACU5sDk-2NeWgp-MBt1O0=MoP1mnH5UgWY1PuYK_YyJTpJ256Q@mail.gmail.com>
From: Mohan Parthasarathy <suruti94@gmail.com>
To: Paul Wouters <paul@xelerance.com>
Cc: Paul Vixie <vixie@isc.org>, dnsext@ietf.org
Subject: Re: [dnsext] draft-mohan-dns-query-xml-00.txt
X-BeenThere: dnsext@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: DNS Extensions working group discussion list <dnsext.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dnsext>, <mailto:dnsext-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/dnsext>
List-Post: <mailto:dnsext@ietf.org>
List-Help: <mailto:dnsext-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dnsext>, <mailto:dnsext-request@ietf.org?subject=subscribe>
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Sender: dnsext-bounces@ietf.org
Errors-To: dnsext-bounces@ietf.org

On Wed, Sep 28, 2011 at 12:32 PM, Paul Wouters <paul@xelerance.com> wrote:
> On Wed, 28 Sep 2011, Mohan Parthasarathy wrote:
>
>> DNSSEC validation is stub resolver is dependent on DNSSEC-aware CPEs,
>> recursive servers etc. Here is a draft that we submitted yesterday to
>> address this problem.
>>
>> http://www.ietf.org/id/draft-mohan-dns-query-xml-00.txt
>>
>> Please send your comments/feedback to the list.
>
> Have you done any research on running DNS over port 80/443? That seems
> to work quite often (after hotspot auth that breaks all dns)
>
> I'm wondering about the difference in working with running dns over http
> on port 80/443 and running plain dns over port 80/443
>

If I want to be able to run both my web service and DNS service from
the same address, then I can't just run DNS alone over 80/443.

> Also, if this is considered a good idea (of which I am not yet convinced),
> why not add a mode similar to the "dnssec chains" proposal to speed things
> up
> for the resolver, as we're already on TCP so response size shouldn't matter
> as much as latency does.
>

I am not sure I understand. It is not about speed. It is about the
stub validator being able to get the DNSSEC records when sitting
behind CPEs and recursive servers (and other middle boxes) that are
not DNSSEC aware.

-mohan


> You can test running dns over port 80/443 using ounbound and forwarding it
> to open.nlnetlabs.nl
>
> Paul
>
_______________________________________________
dnsext mailing list
dnsext@ietf.org
https://www.ietf.org/mailman/listinfo/dnsext