On Wed, Dec 14, 2016 at 10:21:13AM +0100,
 Shane Kerr <[email protected]> wrote 
 a message of 90 lines which said:

> > Given that a fallback to TCP/TLS is likely needed even if the
> > right answer is QUIC, and given that however the WG decide to
> > address server authentication and session management should work
> > just as well for TCP/TLS as for QUIC... maybe the WG could
> > experiment with TCP/TLS in the medium term with the longer term
> > plan being to move to QUIC with TCP/TLS as the fallback whenever
> > QUIC seems ready for primetime.
...
> This seems reasonable to me. It basically implies that we should
> insure some small amount of agility in the encrypted channel, which
> seems like a good idea anyway.

I smell practical and programming issues there. Soon,we will have four
ways for a DNS client to talk to a name server, UDP, TCP, TLS+TCP,
DTLS+UDP, and no guidance on how to combine them, in which order to do
so (think of the "happy eyeballs" problem), what to do if some
fail... Adding a fifth, QUIC+TLS, won't help. What will the poor
client be supposed to do?

_______________________________________________
dns-privacy mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/dns-privacy

Reply via email to