Re: [OPSAWG] AD review of draft-ietf-opsawg-mud-iot-dns-considerations-08

mohamed.boucadair@orange.com Wed, 18 October 2023 16:32 UTC

Return-Path: <mohamed.boucadair@orange.com>
X-Original-To: opsawg@ietfa.amsl.com
Delivered-To: opsawg@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id D5B0DC151066; Wed, 18 Oct 2023 09:32:23 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.104
X-Spam-Level:
X-Spam-Status: No, score=-2.104 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H5=0.001, RCVD_IN_MSPIKE_WL=0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01, UNPARSEABLE_RELAY=0.001, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=orange.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Qr17szQO3KBe; Wed, 18 Oct 2023 09:32:20 -0700 (PDT)
Received: from smtp-out.orange.com (smtp-out.orange.com [80.12.210.123]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 60623C15198D; Wed, 18 Oct 2023 09:30:05 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=orange.com; i=@orange.com; q=dns/txt; s=orange002; t=1697646606; x=1729182606; h=to:cc:subject:date:message-id:references:in-reply-to: mime-version:content-transfer-encoding:from; bh=a576kbA5FXK4MKAreYLXokBjbETgXdy70IWiinAQCjM=; b=mUbXfcK2XqFB36aVpLSxl4xT14D6XC8sYsamR/VM/CqlspP7Bj/uwj8A ARO4swaYPHvO1SunHXdeFq1Pvrdu5guib/dXyv7bdBr1iNN6p9l0r9oCq ALz7HnqICpxUarsrAU5D2hML426uY+7q711nHnS92M35+nU8UW6ooWWnM XeqJPGdKs8CMc7+ae1ak4wqfPafkwWMfAhKrIuDQs5y/z5r8FrsUHrEUD fflN96ykCQwmgK8JY43lj/V5cgS5DnSfRsan6v+zmKTPFqzNuW2PrMdoz YRUiTngDY6D4I1Cx4UdbPlyCmdb94Q6MY7qGgTZHLAD4gubf5acKj9zXW Q==;
Received: from unknown (HELO opfedv1rlp0c.nor.fr.ftgroup) ([x.x.x.x]) by smtp-out.orange.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 18 Oct 2023 18:30:04 +0200
Received: from unknown (HELO opzinddimail1.si.francetelecom.fr) ([x.x.x.x]) by opfedv1rlp0c.nor.fr.ftgroup with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 18 Oct 2023 18:30:03 +0200
Received: from opzinddimail1.si.francetelecom.fr (unknown [127.0.0.1]) by DDEI (Postfix) with ESMTP id 73DB1DE82125; Wed, 18 Oct 2023 18:30:03 +0200 (CEST)
Received: from opzinddimail1.si.francetelecom.fr (unknown [127.0.0.1]) by DDEI (Postfix) with ESMTP id 5836DDE82152; Wed, 18 Oct 2023 18:30:03 +0200 (CEST)
Received: from smtp-out365.orange.com (unknown [x.x.x.x]) by opzinddimail1.si.francetelecom.fr (Postfix) with ESMTPS; Wed, 18 Oct 2023 18:30:03 +0200 (CEST)
Received: from mail-db3eur04lp2051.outbound.protection.outlook.com (HELO EUR04-DB3-obe.outbound.protection.outlook.com) ([104.47.12.51]) by smtp-out365.orange.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 18 Oct 2023 18:30:03 +0200
Received: from DU2PR02MB10160.eurprd02.prod.outlook.com (2603:10a6:10:49b::6) by DB9PR02MB8046.eurprd02.prod.outlook.com (2603:10a6:10:370::9) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.6907.23; Wed, 18 Oct 2023 16:30:01 +0000
Received: from DU2PR02MB10160.eurprd02.prod.outlook.com ([fe80::82bf:2264:fe9e:512e]) by DU2PR02MB10160.eurprd02.prod.outlook.com ([fe80::82bf:2264:fe9e:512e%4]) with mapi id 15.20.6907.022; Wed, 18 Oct 2023 16:30:01 +0000
From: mohamed.boucadair@orange.com
X-TM-AS-ERS: 10.106.160.159-127.5.254.253
X-TM-AS-SMTP: 1.0 c210cC1vdXQzNjUub3JhbmdlLmNvbQ== bW9oYW1lZC5ib3VjYWRhaXJAb 3JhbmdlLmNvbQ==
X-DDEI-TLS-USAGE: Used
Authentication-Results: smtp-out365.orange.com; dkim=none (message not signed) header.i=none; spf=Fail smtp.mailfrom=mohamed.boucadair@orange.com; spf=Pass smtp.helo=postmaster@EUR04-DB3-obe.outbound.protection.outlook.com
Received-SPF: Fail (smtp-in365b.orange.com: domain of mohamed.boucadair@orange.com does not designate 104.47.12.51 as permitted sender) identity=mailfrom; client-ip=104.47.12.51; receiver=smtp-in365b.orange.com; envelope-from="mohamed.boucadair@orange.com"; x-sender="mohamed.boucadair@orange.com"; x-conformance=spf_only; x-record-type="v=spf1"; x-record-text="v=spf1 ip4:80.12.66.32/28 ip4:80.12.210.96/28 ip4:80.12.70.34/31 ip4:80.12.70.36 include:spfa.orange.com include:spfb.orange.com include:spfc.orange.com include:spfd.orange.com include:spfe.orange.com include:spff.orange.com include:spf6a.orange.com include:spffed-ip.orange.com include:spffed-mm.orange.com -all"
Received-SPF: Pass (smtp-in365b.orange.com: domain of postmaster@EUR04-DB3-obe.outbound.protection.outlook.com designates 104.47.12.51 as permitted sender) identity=helo; client-ip=104.47.12.51; receiver=smtp-in365b.orange.com; envelope-from="mohamed.boucadair@orange.com"; x-sender="postmaster@EUR04-DB3-obe.outbound.protection.outlook.com"; x-conformance=spf_only; x-record-type="v=spf1"; x-record-text="v=spf1 ip4:40.92.0.0/15 ip4:40.107.0.0/16 ip4:52.100.0.0/14 ip4:104.47.0.0/17 ip6:2a01:111:f400::/48 ip6:2a01:111:f403::/49 ip6:2a01:111:f403:8000::/50 ip6:2a01:111:f403:c000::/51 ip6:2a01:111:f403:f000::/52 -all"
IronPort-Data: A9a23:6xiqVqJBW2l+oq0WFE+RDpIlxSXFcZb7ZxGr2PjKsXjdYENS1DIDy TAbC2+Cbq3eMDCmf9t+aN/j9EsFusTTyNNhGgForCE8RH908seUXt7xwmUcns+xwm8vaGo9s q3yv/GZdJhcokf0/0vraP64xZVF/fngbqLmD+LZMTxGSwZhSSMw4TpugOdRbrRA2bBVOCvT/ 4upyyHjEAX9gWUtajtEs/jrRC5H55wehhtJ5zTSWtgb5Dcyp1FNZLoDKKe4KWfPQ4U8NoZWk M6akdlVVkuAl/scIovNfoTTKyXmcZaLVeS6sUe6boD56vR0So7e5Y5gXBYUQR8/ZzxkBLmdw v0V3XC7YV9B0qEhBI3xXjEAexySM5Gq95f5fijhg8bPwHfDfmnM6cpJPmFxJdQXr7Mf7WFmr ZT0KRggUyrb26ea6un+TeNhwMM+MMPsIYUT/Gl6yi3UBuonRpaFRLjW4dhf33E7gcUm8fT2P pJFL2YwKk2aJUAWUrsUIMpWcOOAg37/ejhVpBSforc86mTazRZZ16LkNtXYPNeNQK25m27B/ DKdrzyhXXn2MvSg0DPb/S73oNPVwwKrG74vDqGDzaN11Qj7Kms7U0RNDgPi+5FVkHWWXtlFA 1cd/CYjqa078gqgR7HVRQK5pGKDuDYXWsFbFKsx7wTl4q3M+A+GCUAFQyJPLts8u6ceSSYj2 EPMnt71C3loqKacVn3Y86qY6DK1JW0ZK3RHbigCVgoJ7sPqvIA0iAnnT9t/HuiylNKdJN3r6 zWDrSx7i79IgNMRj/m/5Qqf3mvqoYXVRAko4AmRRnii8g5yeI+iYcqv9ETf6vFDao2eSzFto UToheCgs7BQP5vRmxaITfctNo6O1dbCKGTT1AsH84Yayxyh/HuqfIZ16T54JVt0PstsRdMPS B6L0e+2zM4LVEZGfZObcKrsUJ9xkviI+cDNE66OM4sWCnRkXFXflByCc3J8yEjMvSDAe4kTJ J2fcMDE4Z0yJfw9pNZab8MQ0Lkw2i0krV4/qLj+xhWjlLaUP3OIU+9ZNEPUNr1gqqSZvA/S7 tBTcdOQzAlSW/H/ZS+R9pMPKVcNLj4wApWeRy1rmgyrcloO9IIJUqC5LVYdl2pNwP09egDgo C/VZ6Og4ACj7UAr0C3TApyZVJvhXIxksVUwNjE2MFCj1hALONj+s/pBKMdsIud4r4SPKMKYq dFUIq1s5dweElz6F8g1N8WVQHFKKET13FPVbnPNjMYXJc4/HFaRkjMbQucf3HJXVXHv7JFWT 0yI0wLQW50YQAp+RM/Edeiip25dTlBM8N+eq3Dge4EJEG21qNYCA3Wo0pcffZtQQT2dnWDy/ 1jNXn8lSRzl+NNdHC/h3v3c8+9E0oJWQiJnIoUsxerubneDozb/nNUovSThVWm1aV4YMZ6KP Y19p8wQ+tVe9LqWm+KQ0oqHzJ7SI/PCmoUCkkFINi6OaF6mTLR9PnOBwM9D8LVXwaNUshe3X UTJ/cRGPbKOO4XuF1t5yM8NcLGYzf9N8tXNxa1dHak4zHcfEHm7vYF6OAOFjiNQarByNevJB M8/7dUO5VXXZgUCbr67s8yMy1mxEw==
IronPort-HdrOrdr: A9a23:majUH6t3M4dg5Sx8jZNgOhvJ7skDTdV00zEX/kB9WHVpm6uj5r iTdZUgpGbJYVMqMk3I9urwW5VoLUmsl6KdgrNhW4tKPjOW3FdARbsKheCD/9SJIUzDH4VmpM BdmsZFebjN5JtB4foSIjPULz/t+ra6GWmT69vj8w==
X-Talos-CUID: 9a23:1MLJMW5fQZIoH8PPVdssyhFERPIvLnLnyXrCA2WHLlRJD6XMRgrF
X-Talos-MUID: 9a23:Wk8HXwTGTV0EgOHnRXTTnTg8O5szxZi0VmFd0qk7odW/DnFvbmI=
X-IronPort-AV: E=Sophos;i="6.03,235,1694728800"; d="scan'208";a="12838007"
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=BeskaD6l/oRmPV8z+4Q6KBrD6AYfoC0T6H/23wN5MBLBoaWPcbXVyUDQxVYB2b0c7vGdehisKvHWy+mANOp95RH6kxIEy5hukVL6hVGfTCMYpoA6t8kFKi4OHRZZwFUxHsU1CovmJY3TxYPXY/lO+fvh2gNPRhGAiNt3hciVUnTVurNay8yAQa+Sv8TfIIWqO8DUBgas+uDy5FhJV/rhG1FEFLlSvNkPBaJzFrzq7bMVQrDarElTZ2N1zkIza52/iEpOhOEZV10HipxEWP4vBPd84Ozl3OvfxCV/eB9+yRCW1t8FtqwqUDOFmqE4D70TglZYMBrOAkVcF0wUQlLtSA==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=MdF0M4yHOvwvb84AVCH/Zn8O6Ba2FJ8TXxExK4b3mHo=; b=IMnnrLADkauQT72UPczSmmsXW+UEm0PPpoicrJK19pVsiog2toCBxEi87GMMgiKgNqdplAx9VddSOl1CznRhHFdOTVk1wh/hv9JAP3beJodjiJkB90N7VGDqTBYdxEmoWFXGMYtmnFNeuX7Jf55mW5xoUOwtkgaL+swjRjcqcr/u/Ub0OkdNvhvessIPHEnjVnfqevlXPlyuRC2H8GzJwIJvwPLX7phhlIZC0Qwrw7oVvlQeM0Lp+AwI7UpRDW/4A+rObdedWmvljc9qVY8U9CqY+ZToN042zaVpEDnZIF/EmbzUixso30fVAxtrTePEWYVDEsH/iGmCm6eUUDXgxQ==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=orange.com; dmarc=pass action=none header.from=orange.com; dkim=pass header.d=orange.com; arc=none
To: Michael Richardson <mcr@sandelman.ca>, "Rob Wilton (rwilton)" <rwilton@cisco.com>
CC: "opsawg@ietf.org" <opsawg@ietf.org>, "draft-ietf-opsawg-mud-iot-dns-considerations@ietf.org" <draft-ietf-opsawg-mud-iot-dns-considerations@ietf.org>
Thread-Topic: [OPSAWG] AD review of draft-ietf-opsawg-mud-iot-dns-considerations-08
Thread-Index: AQHaAdkO9B0g5HY0WUq5Z+hurI5AjrBPuF5g
Content-Class:
Date: Wed, 18 Oct 2023 16:30:01 +0000
Message-ID: <DU2PR02MB10160547DD3B4D7A81EF211F488D5A@DU2PR02MB10160.eurprd02.prod.outlook.com>
References: <BY5PR11MB419663E50375EFC179E7CE65B5D2A@BY5PR11MB4196.namprd11.prod.outlook.com> <12876.1697643420@localhost>
In-Reply-To: <12876.1697643420@localhost>
Accept-Language: fr-FR, en-US
Content-Language: fr-FR
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
msip_labels: MSIP_Label_07222825-62ea-40f3-96b5-5375c07996e2_Enabled=true; MSIP_Label_07222825-62ea-40f3-96b5-5375c07996e2_SetDate=2023-10-18T16:13:59Z; MSIP_Label_07222825-62ea-40f3-96b5-5375c07996e2_Method=Privileged; MSIP_Label_07222825-62ea-40f3-96b5-5375c07996e2_Name=unrestricted_parent.2; MSIP_Label_07222825-62ea-40f3-96b5-5375c07996e2_SiteId=90c7a20a-f34b-40bf-bc48-b9253b6f5d20; MSIP_Label_07222825-62ea-40f3-96b5-5375c07996e2_ActionId=0918929f-f756-4480-a8eb-c6268ef9c33d; MSIP_Label_07222825-62ea-40f3-96b5-5375c07996e2_ContentBits=0
x-ms-publictraffictype: Email
x-ms-traffictypediagnostic: DU2PR02MB10160:EE_|DB9PR02MB8046:EE_
x-ms-office365-filtering-correlation-id: 7a6ba79a-4b3c-4324-8cdc-08dbcff779f1
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: Q8ddibEfipE7RPHuCFcsnyuxqsYjuID2sVFH3MVtQFt8IwR2io6lFkK1Oj0b8bQdIiCxpUAUjSGA+cp91Xrr3y5Ps4fylaru+dVr+AMyL64AdLB1ZR7Rxnvw3zA4K/e7tU4DXofJzl5pGB+HJP6HbBJq9SiR2rYbGuAk3Vg9YfDJiZ6YRlVQSHpcLGkBATlq3y72RgczA/cg9DyO+5hzjPcK9RC3hALzBNIFRQhV0bIwTQuFm/NEz8DFax+qDechnRaUwSHdXVQGd3ThhmBZm0OTx3YngXHJbyoUgA9mcfxaE58sqnYpxG66XRBYoEEWm4GAHno61lQY1Cv/ucTnVoY6DSRG4+3pDO7FJ3Rb721rzTzsQHFga8VqlnFccWFNb6ot/ObL3WR7G5P71JwJCPGX4un/W2aAwlosTGZIIPwtDd9OQIS+b6rBMq5Dnv4KYn9oN3uKzCd2AkAhYLEG9ekRAs02fc+u810pT7kRp/z9HGMrdHN4tfXtAi6RhEm9Dgi+gMBVGMMdr+Th3c5DEJZNovueyLp5RsT0kpMrAFjq+3+wRojG5tkfHXGR58hVVr5K/w9apy9JW/4BTY4adGXFCqZYRFOKzBpj7ebom9lybAtKQ/RMI2zrgB+QgB7qG1kSn4gwHGq3iqTCh/B8cw==
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:DU2PR02MB10160.eurprd02.prod.outlook.com; PTR:; CAT:NONE; SFS:(13230031)(39860400002)(136003)(346002)(366004)(396003)(376002)(230922051799003)(64100799003)(186009)(451199024)(1800799009)(5660300002)(316002)(64756008)(66476007)(66946007)(110136005)(54906003)(66446008)(76116006)(66556008)(55016003)(478600001)(8936002)(4326008)(8676002)(122000001)(38100700002)(38070700005)(83380400001)(66574015)(52536014)(9686003)(86362001)(33656002)(41300700001)(6506007)(7696005)(71200400001)(2906002)(26005); DIR:OUT; SFP:1102;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: E95FRQdyH8vHYotF6RAFrdKip+QQdDaArz5Uf+rF+0Z2itnGeOQkwyojGamYcQm29z3D9M5PevNkQ8YsD/aSrU2TQcoBQxECTfNo7WJBQbogy/eQTYd1gDgU9OfIUfgviFgFFyFmEBKPfVGFKTbNcBmdzer31dwu2+hoOdz4tQitFNg4EGidDpNZVCEI6PUpG75m6lHURH2DHM3VvlBcxRkewOcLkaaziQ5tNohtNx3/iZUuUm76V0POW5AAb8MXzDwc6iiwntJL1m0rOy3ro4HzkW/PiGcBjFmio1Q6TY6X1XV5P2gBt4Ng+lIdRM78j8tfzTvpJsDoj/eNdFeAFVP9gjC3Inac1jiWu0a+U1/tnQ5DkJLfMJOwOhrLTix6/ePCbCaaBKGdE1TiqDiTVaGAwzw5IzDo6tJYzj16aGVhY4EXuOcVS9Ti39EDciKaO1Fk/eNXVc8MafOPN71xFPWPpFpKtaoFLqWOzqdenCW4dNKwl9dLRSe0btR/nVvCPVC8+r/KMUiT4rgyTiyxssAMIjbFJmLgpUxYXiEO/+H8Vp6YMb4+uegJVaJuv9zap8Y+vuoMGOn9lXfKM++Q1Ef+Ucthewz4xpiK2oLBLTrQ3O+b5yk5jDqyy2Gg3ZtDFQEFyn3YOSJiNopKKJ4wfsCafojaGQH10epLXNA2d+kYMstyCV2mox0swoyH5L0jwgovwkU8XpsHgRHe9vHtBhJ3/Dzv+271BIC3JY1t60M+Dsi+xw6X1Doua5ag/XOz4C/01XubT1AMXvKJH/iVPteLABbMOG6A0wHHeLt5mIXYzgOx6WvbJwgq1QcLFCd0HUEJQtnWV9joVDdUufEaTl+NvBy92+KR/rNuep7vFNnRW2lFPf4spQSHxR7bC3jMT3hTRwyBmwh+pbr8X04GyXk+Dy4JJKqZa5SfvkIShxa7W+4iOn61YumyaQPGS43dntPGgSxKxghIcS5EfsoPHgiweiWCbRPO8IBgd9+u990LCgdwTVhC0ZAD6wwuOUA1Tuedlej3oRmwkkQFiBiQYfGuS0tMeWD4HS3rtfTwSkcdLrj+2A1Pq8+CyaPQEqzd/t0ikGKEIt6x8JMoZ6EV6SQaJ4kuR89Smf5f853XiB2hLpmRV5MWoOnxgoXmsDV7FBliNHa3deNQuuV8UXkmjrhyaTg7MIhbKRfMtwrF4XFtF/0/7d356AdkbHRO3EM7OCMQe4GFQ/lK4F5nL6iZGnv8bUEipD6ucH3npW8ecYd5xUncGz5h7p2BMiG7QBp9+pKYrXRmIlCNXbZQ+q3dTHAoaml8pA/MKCvDZ6pfZVfgL1U7ma9pCt7Wy5V69UFjt9bzE/jr5Y3s6yBA/xC0ZzknZQDhDjXQVoDnzs7MRbx9+2hqIhEJ2Fu92lfgsDPMSOkYXgaT8RUqhggLpoRN7z5wwKSmNGFJexiHUKAhwKkAHBIFk2bms/ka2qVZvxkTVoyil8+8gbODrz9rgJ1lYjC5sd3nSpYRLFpyjzmnLgngGirCgM+CxdF+WN37ER5/IyEn7qYVvRwZZbC2oG2pyTpOui204+gbpsO8oF5i/vknt1R24YYqwJUCtZ7EN5x5XZPolAcL1y4N4WhkjoF1qA==
Content-Type: text/plain; charset="iso-8859-1"
MIME-Version: 1.0
X-OriginatorOrg: orange.com
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: DU2PR02MB10160.eurprd02.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: 7a6ba79a-4b3c-4324-8cdc-08dbcff779f1
X-MS-Exchange-CrossTenant-originalarrivaltime: 18 Oct 2023 16:30:01.2317 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 90c7a20a-f34b-40bf-bc48-b9253b6f5d20
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: RjZ05SeOIE/EtE+pxD4eAhWA44LGtCanidxGHbwSHwFSYe45fed8UUyVU2HWVRR/x6Wi/ZBMDvYNhsRSeoA+aPY1BSFM3whfiGgGoxDtSo0=
X-MS-Exchange-Transport-CrossTenantHeadersStamped: DB9PR02MB8046
X-TM-AS-ERS: 10.106.160.159-127.5.254.253
X-TM-AS-SMTP: 1.0 c210cC1vdXQzNjUub3JhbmdlLmNvbQ== bW9oYW1lZC5ib3VjYWRhaXJAb 3JhbmdlLmNvbQ==
X-TMASE-Version: DDEI-5.1-9.0.1002-27944.000
X-TMASE-Result: 10--26.028300-10.000000
X-TMASE-MatchedRID: 6lay9u8oTUOOhHkPCXAFR9+pUF0HsjxRlwT0XposETU/gf7afIrQU/to 1vMdVRxRWzJZFaSQW7fAG0wixVG44sgsRQTLEO1AueYB1mSXzr9PnKxAOPp4WcfASe7knCttwjX tSQL2c2L6iqTn69km60HeTOGcbcykU6TbCJprNmX+xRIVoKNMvPioIsi7Sa0gS6QizeDUeN7w0z afNNap1PKd3Vf6F5PzyLQvRjhwzYtWFHN8/yH3Loa04/TlRM8JxddRrnptOedlEv6AItKWF2s/q wVzgkZcJ6rAI3ENw+wKzKWGtnkHHx2BfeLATnEW+ScJ/ljmM9jcAmu1xqeetvUacbYKkpXEjLjm Xfj1QRniHhtnlhNmRFnntZNsRr0E5VtV90uxxtdANB89sV0bJ30tCKdnhB58vHkdPhnNpj8hPea VMHHsTOMJ4Tm/iUfkQyJGPQdwPixWdFebWIc3VsRB0bsfrpPI6T/LTDsmJmg=
X-TMASE-SNAP-Result: 1.821001.0001-0-1-22:0,33:0,34:0-0
X-TMASE-INERTIA: 0-0;;;;
X-TMASE-XGENCLOUD: b8f3d204-5caa-4a7b-a203-714fbd092ce3-0-0-200-0
Content-Transfer-Encoding: quoted-printable
Archived-At: <https://mailarchive.ietf.org/arch/msg/opsawg/ON93LktrO4piPqLqdqUTS_2eOEY>
Subject: Re: [OPSAWG] AD review of draft-ietf-opsawg-mud-iot-dns-considerations-08
X-BeenThere: opsawg@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: OPSA Working Group Mail List <opsawg.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/opsawg>, <mailto:opsawg-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/opsawg/>
List-Post: <mailto:opsawg@ietf.org>
List-Help: <mailto:opsawg-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/opsawg>, <mailto:opsawg-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 18 Oct 2023 16:32:23 -0000

Hi Michael,

(Focusing on this specific comment and part of the text)

* I don't think we can leave the ref to the bootstrap I-D as that was abandoned since a while. I was delete that citation. 
* Not sure why DoT/DoH is explicitly mentioned in that text. I think the reasoning should be more about encrypted DNS in general. 
* I don't parse what is meant by " includes using DoT/DoH is a local decision, but a locally provided
   DoT server SHOULD be used,"
* In the text right after, you have the following: 

   The ADD WG is currently only focusing on insecure discovery
   mechanisms like DHCP/RA [I-D.ietf-add-dnr] and DNS based discovery
   mechanisms ([I-D.ietf-add-ddr]).

I would refresh the text as both DNR and DDR are to be published as RFCs.

* Also, not sure it is worth mentioning here given the scope, but secure discovery is possible with draft-ietf-ipsecme-add-ike. 
* Not sure I would maintain "Use of public QuadX resolver" as there are public resolvers that are not Quads
* "This should include the port numbers (53, 853 for DoT, 443 for DoH)": these are default ports numbers. Alternate port numbers can be used and thus be configured. 

Aaah, BTW please remove this entry:

   [I-D.peterson-doh-dhcp]
              Peterson, T., "DNS over HTTP resolver announcement Using
              DHCP or Router Advertisements", Work in Progress,
              Internet-Draft, draft-peterson-doh-dhcp-01, 21 October
              2019, <https://www.ietf.org/archive/id/draft-peterson-doh-
              dhcp-01.txt>.

and double check the normative references. I'm sure those at least are not normative: 

   [Akamai]   "Akamai", 2019,
              <https://en.wikipedia.org/wiki/Akamai_Technologies>.

   [AmazonS3] "Amazon S3", 2019,
              <https://en.wikipedia.org/wiki/Amazon_S3>.

   [I-D.ietf-dnsop-terminology-ter]
              Hoffman, P. E., "Terminology for DNS Transports and
              Location", Work in Progress, Internet-Draft, draft-ietf-
              dnsop-terminology-ter-02, 3 August 2020,
              <https://www.ietf.org/archive/id/draft-ietf-dnsop-
              terminology-ter-02.txt>.

Cheers,
Med

> -----Message d'origine-----
> De : OPSAWG <opsawg-bounces@ietf.org> De la part de Michael Richardson
> Envoyé : mercredi 18 octobre 2023 17:37
> À : Rob Wilton (rwilton) <rwilton@cisco.com>
> Cc : opsawg@ietf.org; draft-ietf-opsawg-mud-iot-dns-
> considerations@ietf.org
> Objet : Re: [OPSAWG] AD review of draft-ietf-opsawg-mud-iot-dns-
> considerations-08
> 
> 
> 
>     > (7) p 11, sec 6.5.  Prefer DNS servers learnt from DHCP/Route
> Advertisements
> 
>     > IoT Devices should prefer doing DNS to the network provided DNS
>     > servers.  Whether this is restricted to Classic DNS (Do53) or
> also
>     > includes using DoT/DoH is a local decision, but a locally
> provided
>     > DoT server SHOULD be used, as recommended by
>     > [I-D.reddy-add-iot-byod-bootstrap].
> 
>     > Should it be DoT/DoH server SHOULD be used, or do you mean to
>     > specifically recommend DoT over DoH here?
> 
> Yeah, the /DoH is missing, and has been added.
> It's that a *local* DoT/DoH is preferred.
> 
____________________________________________________________________________________________________________
Ce message et ses pieces jointes peuvent contenir des informations confidentielles ou privilegiees et ne doivent donc
pas etre diffuses, exploites ou copies sans autorisation. Si vous avez recu ce message par erreur, veuillez le signaler
a l'expediteur et le detruire ainsi que les pieces jointes. Les messages electroniques etant susceptibles d'alteration,
Orange decline toute responsabilite si ce message a ete altere, deforme ou falsifie. Merci.

This message and its attachments may contain confidential or privileged information that may be protected by law;
they should not be distributed, used or copied without authorisation.
If you have received this email in error, please notify the sender and delete this message and its attachments.
As emails may be altered, Orange is not liable for messages that have been modified, changed or falsified.
Thank you.