Dear DNSOP, Please review our new DNS Server Cookies draft.
It has an updated Client Cookie construction section and a new Security and Privacy section that elaborates in particular on the considerations for Client Cookie construction. Op 19-11-2019 om 00:01 schreef internet-dra...@ietf.org: > > A New Internet-Draft is available from the on-line Internet-Drafts > directories. > This draft is a work item of the Domain Name System Operations WG of the IETF. > > Title : Interoperable Domain Name System (DNS) Server > Cookies > Authors : Ondrej Sury > Willem Toorop > Donald E. Eastlake 3rd > Mark Andrews > Filename : draft-ietf-dnsop-server-cookies-02.txt > Pages : 16 > Date : 2019-11-18 > > Abstract: > DNS cookies, as specified in RFC 7873, are a lightweight DNS > transaction security mechanism that provides limited protection to > DNS servers and clients against a variety of denial-of-service and > amplification, forgery, or cache poisoning attacks by off-path > attackers. > > This document provides precise directions for creating Server Cookies > so that an anycast server set including diverse implementations will > interoperate with standard clients. > > This document updates [RFC7873] > > > The IETF datatracker status page for this draft is: > https://datatracker.ietf.org/doc/draft-ietf-dnsop-server-cookies/ > > There are also htmlized versions available at: > https://tools.ietf.org/html/draft-ietf-dnsop-server-cookies-02 > https://datatracker.ietf.org/doc/html/draft-ietf-dnsop-server-cookies-02 > > A diff from the previous version is available at: > https://www.ietf.org/rfcdiff?url2=draft-ietf-dnsop-server-cookies-02 > > > Please note that it may take a couple of minutes from the time of submission > until the htmlized version and diff are available at tools.ietf.org. > > Internet-Drafts are also available by anonymous FTP at: > ftp://ftp.ietf.org/internet-drafts/ > > _______________________________________________ > DNSOP mailing list > DNSOP@ietf.org > https://www.ietf.org/mailman/listinfo/dnsop > _______________________________________________ DNSOP mailing list DNSOP@ietf.org https://www.ietf.org/mailman/listinfo/dnsop