(With no hats...) On 13/12/16 19:44, Christian Huitema wrote: > On Tuesday, December 13, 2016 11:16 AM, Paul Hoffman wrote: >> >> If what we invent has better characteristics than DTLS or TLS, that >> means that the TLS WG failed to find something that we could. That seems >> *incredibly* unlikely, given the people active in the two WGs. > > Actually, QUIC might provide an answer, if you are willing to wait a couple > years.
Yeah, I think QUIC might be good here. And maybe the 2 years isn't so bad either... Given that a fallback to TCP/TLS is likely needed even if the right answer is QUIC, and given that however the WG decide to address server authentication and session management should work just as well for TCP/TLS as for QUIC... maybe the WG could experiment with TCP/TLS in the medium term with the longer term plan being to move to QUIC with TCP/TLS as the fallback whenever QUIC seems ready for primetime. There're probably some flaws in the above, but it might be a plan. Cheers, S. > Runs over UDP, uses TLS 1.3 key negotiation, encrypts pretty much > everything, enables 0-RTT, and manages multiple flows. A one-query per > QUIC-flow model would provide better service than TCP because it does not > suffer from head of queue blocking, and better service than DTCP because it > does not limit the amount of data sent in queries and response. But of > course, the QUIC WG is just getting started, so it will probably take two > years before we can start deployment of something like DNS over QUIC. > > -- Christian Huitema > > > > _______________________________________________ > dns-privacy mailing list > [email protected] > https://www.ietf.org/mailman/listinfo/dns-privacy >
smime.p7s
Description: S/MIME Cryptographic Signature
_______________________________________________ dns-privacy mailing list [email protected] https://www.ietf.org/mailman/listinfo/dns-privacy
