Stephen, At 2016-12-13 22:40:09 +0000 Stephen Farrell <[email protected]> wrote:
> (With no hats...) > > On 13/12/16 19:44, Christian Huitema wrote: > > On Tuesday, December 13, 2016 11:16 AM, Paul Hoffman wrote: > >> > >> If what we invent has better characteristics than DTLS or TLS, that > >> means that the TLS WG failed to find something that we could. That seems > >> *incredibly* unlikely, given the people active in the two WGs. > > > > Actually, QUIC might provide an answer, if you are willing to wait a couple > > years. > > Yeah, I think QUIC might be good here. And maybe the 2 years > isn't so bad either... > > Given that a fallback to TCP/TLS is likely needed even if the > right answer is QUIC, and given that however the WG decide to > address server authentication and session management should > work just as well for TCP/TLS as for QUIC... maybe the WG could > experiment with TCP/TLS in the medium term with the longer > term plan being to move to QUIC with TCP/TLS as the fallback > whenever QUIC seems ready for primetime. > > There're probably some flaws in the above, but it might be a > plan. This seems reasonable to me. It basically implies that we should insure some small amount of agility in the encrypted channel, which seems like a good idea anyway. This approach is independent of the trust problem, which I think is trickier, but it means we could in principle get working implementations in the near/medium-term. :) Cheers, -- Shane
pgpvZKR2ilx0N.pgp
Description: OpenPGP digital signature
_______________________________________________ dns-privacy mailing list [email protected] https://www.ietf.org/mailman/listinfo/dns-privacy
