Alissa Cooper has entered the following ballot position for
draft-ietf-dnsop-dns-capture-format-08: No Objection

When responding, please keep the subject line intact and reply to all
email addresses included in the To and CC lines. (Feel free to cut this
introductory paragraph, however.)


Please refer to https://www.ietf.org/iesg/statement/discuss-criteria.html
for more information about IESG DISCUSS and COMMENT positions.


The document, along with other ballot positions, can be found here:
https://datatracker.ietf.org/doc/draft-ietf-dnsop-dns-capture-format/



----------------------------------------------------------------------
COMMENT:
----------------------------------------------------------------------

I support Benjamin's first DISCUSS point. In addition to documenting the
privacy considerations, I think it's important for this document to be crystal
clear about who is meant to be doing the data collection -- namely, the server
operator. There are some statements in the document that otherwise could be
construed to be encouraging third-party passive monitoring of DNS traffic
without explaining why, which seems like a problem:

Section 1:

"There has long been a need to collect DNS queries and responses on
   authoritative and recursive name servers for monitoring and analysis."

Section 3:

"In an ideal world, it would be optimal to collect full packet
   captures of all packets going in or out of a name server."


_______________________________________________
DNSOP mailing list
DNSOP@ietf.org
https://www.ietf.org/mailman/listinfo/dnsop

Reply via email to