Re: [dnsext] draft-mohan-dns-query-xml-00.txt

Paul Wouters <paul@xelerance.com> Wed, 28 September 2011 19:31 UTC

Return-Path: <dnsext-bounces@ietf.org>
X-Original-To: namedroppers-archive-gleetwall6@lists.ietf.org
Delivered-To: ietfarch-namedroppers-archive-gleetwall6@ietfa.amsl.com
Received: from ietfa.amsl.com (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 23B9111E811E; Wed, 28 Sep 2011 12:31:31 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1317238291; bh=Vx4rKzDjiJ28JHi/mVlbsTq1mPKkU+Dtn1PVrs+3Jqo=; h=Date:From:To:In-Reply-To:Message-ID:References:MIME-Version:Cc: Subject:List-Id:List-Unsubscribe:List-Archive:List-Post:List-Help: List-Subscribe:Content-Transfer-Encoding:Content-Type:Sender; b=CGszN3CUIfPcYX2NJSlk/q8epclcXf4lK9L2Xa+bcXSrXh7evPdTbwK8rochnIE9F NaXsrXoNCWuarLHexOEXjtrMeDzDgcvVsBl2LOkbk+3/tYbzG0JbETjnvQyADSD/PE 7UPx7kmk7kQAgwXx3kG1m1qh0KHpZdfrTF1u2Rtg=
X-Original-To: dnsext@ietfa.amsl.com
Delivered-To: dnsext@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 5C45411E811A for <dnsext@ietfa.amsl.com>; Wed, 28 Sep 2011 12:31:28 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -6.504
X-Spam-Level:
X-Spam-Status: No, score=-6.504 tagged_above=-999 required=5 tests=[AWL=0.095, BAYES_00=-2.599, RCVD_IN_DNSWL_MED=-4]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id EjZDCGucor4z for <dnsext@ietfa.amsl.com>; Wed, 28 Sep 2011 12:31:27 -0700 (PDT)
Received: from newtla.xelerance.com (newtla.xelerance.com [193.110.157.143]) by ietfa.amsl.com (Postfix) with ESMTP id 7D33311E811D for <dnsext@ietf.org>; Wed, 28 Sep 2011 12:31:27 -0700 (PDT)
Received: from newtla.xelerance.com (newtla.xelerance.com [127.0.0.1]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by newtla.xelerance.com (Postfix) with ESMTP id DDAFF572F9; Wed, 28 Sep 2011 15:32:45 -0400 (EDT)
Date: Wed, 28 Sep 2011 15:32:45 -0400 (EDT)
From: Paul Wouters <paul@xelerance.com>
To: Mohan Parthasarathy <suruti94@gmail.com>
In-Reply-To: <CACU5sDnBx5AijEgFXKNPjtcVdtBnBJamsn-f_ye0Jm3TQq0mvw@mail.gmail.com>
Message-ID: <alpine.LFD.1.10.1109281525430.25654@newtla.xelerance.com>
References: <CACU5sDnBx5AijEgFXKNPjtcVdtBnBJamsn-f_ye0Jm3TQq0mvw@mail.gmail.com>
User-Agent: Alpine 1.10 (LFD 962 2008-03-14)
MIME-Version: 1.0
Cc: Paul Vixie <vixie@isc.org>, dnsext@ietf.org
Subject: Re: [dnsext] draft-mohan-dns-query-xml-00.txt
X-BeenThere: dnsext@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: DNS Extensions working group discussion list <dnsext.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dnsext>, <mailto:dnsext-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/dnsext>
List-Post: <mailto:dnsext@ietf.org>
List-Help: <mailto:dnsext-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dnsext>, <mailto:dnsext-request@ietf.org?subject=subscribe>
Content-Transfer-Encoding: 7bit
Content-Type: text/plain; charset="us-ascii"; Format="flowed"
Sender: dnsext-bounces@ietf.org
Errors-To: dnsext-bounces@ietf.org

On Wed, 28 Sep 2011, Mohan Parthasarathy wrote:

> DNSSEC validation is stub resolver is dependent on DNSSEC-aware CPEs,
> recursive servers etc. Here is a draft that we submitted yesterday to
> address this problem.
>
> http://www.ietf.org/id/draft-mohan-dns-query-xml-00.txt
>
> Please send your comments/feedback to the list.

Have you done any research on running DNS over port 80/443? That seems
to work quite often (after hotspot auth that breaks all dns)

I'm wondering about the difference in working with running dns over http
on port 80/443 and running plain dns over port 80/443

Also, if this is considered a good idea (of which I am not yet convinced),
why not add a mode similar to the "dnssec chains" proposal to speed things up
for the resolver, as we're already on TCP so response size shouldn't matter
as much as latency does.

You can test running dns over port 80/443 using ounbound and forwarding it
to open.nlnetlabs.nl

Paul
_______________________________________________
dnsext mailing list
dnsext@ietf.org
https://www.ietf.org/mailman/listinfo/dnsext