Re: [DNSOP] Fundamental ANAME problems

2018-11-05 Thread manu tman
I like the ANAME idea and find it overall simple if what we are trying to solve is CNAME at apex. If what is being solved is per service then it is another story. As much as I like it, I find the resolution at the auth nameserver a bad thing for a couple of reasons. As has been mentioned before: 1

Re: [DNSOP] Draft for dynamic discovery of secure resolvers

2018-08-20 Thread manu tman
I am going to echo my original comment on the draft as it may have been lost in this long thread and it will make sense to keep this close to related convo. ``` As for feedback on the draft options. - Section 2.3: Why DoH has no option data? The IP from the DNS recursive name server option merely

Re: [DNSOP] Draft for dynamic discovery of secure resolvers

2018-08-19 Thread manu tman
On Sun, Aug 19, 2018 at 4:46 PM Ted Lemon wrote: > A user who relies on the dhcp server for dns server info is no worse off. > The problem is that if your host lets the dhcp server override the DoT or > DoH configuration you entered manually, you are a lot worse off. > This seems to be a static

Re: [DNSOP] Draft for dynamic discovery of secure resolvers

2018-08-18 Thread manu tman
I am going to focus back on the draft itself. While the discussion around centralizing DNS to 3rd party vs local ISP (or any other alternatives) is worth having, it is a fact that most people get their DNS server set using DHCP. the current state is that all you will get are addresses that you can

Re: [DNSOP] Call for Adoption: draft-bortzmeyer-rfc7816bis

2018-07-26 Thread manu tman
On Tue, Jul 24, 2018 at 9:32 AM Tim Wicinski wrote: > > We discussed this and there appears to be support to adopt this, with > the caveat of adding more content to the section on Operational > Considerations. > > > This starts a Call for Adoption for draft-bortzmeyer-rfc7816bis > > The draft is

Re: [DNSOP] QNAME minimisation on the standards track?

2018-07-20 Thread manu tman
That's a great feedback Jonathan! Thanks Manu On Fri, Jul 20, 2018 at 6:40 AM Jonathan Reed wrote: > > On Tue, 17 Jul 2018, manu tman wrote: > > > I'd like to see this standardized too. > > Side note: I would also be interested to get a return of experienc

Re: [DNSOP] QNAME minimisation on the standards track?

2018-07-17 Thread manu tman
I'd like to see this standardized too. Side note: I would also be interested to get a return of experience from people operating qname minimization at scale, the type of issues encountered, what are the ratios of such errors hint @marek :) Manu On Tue, Jul 17, 2018 at 2:35 PM Paul Wouters w

Re: [DNSOP] [Doh] Resolverless DNS Side Meeting in Montreal

2018-07-10 Thread manu tman
On Mon, Jul 9, 2018 at 7:49 PM Patrick McManus wrote: > > *We'll do the meeting over 1 hour in the Dorchester room from 16:30 to > 17:30 on Monday July 16th.* > Will it be recorded and will there be everything set for remote participants? Manu ___ DNS

Re: [DNSOP] Call for Adoption: draft-huston-kskroll-sentinel

2017-11-16 Thread manu tman
> the draft uses Vnew Vold Vleg and nonV without description. > that makes it hard for me as I still do not fully understand the idea ... Well it is defined/described in section 3 but I agree that a high level explanation in the terminology section would not hurt. Manu ___