On Wed, Dec 14, 2016 at 10:21:13AM +0100, Shane Kerr <[email protected]> wrote a message of 90 lines which said:
> > Given that a fallback to TCP/TLS is likely needed even if the > > right answer is QUIC, and given that however the WG decide to > > address server authentication and session management should work > > just as well for TCP/TLS as for QUIC... maybe the WG could > > experiment with TCP/TLS in the medium term with the longer term > > plan being to move to QUIC with TCP/TLS as the fallback whenever > > QUIC seems ready for primetime. ... > This seems reasonable to me. It basically implies that we should > insure some small amount of agility in the encrypted channel, which > seems like a good idea anyway. I smell practical and programming issues there. Soon,we will have four ways for a DNS client to talk to a name server, UDP, TCP, TLS+TCP, DTLS+UDP, and no guidance on how to combine them, in which order to do so (think of the "happy eyeballs" problem), what to do if some fail... Adding a fifth, QUIC+TLS, won't help. What will the poor client be supposed to do? _______________________________________________ dns-privacy mailing list [email protected] https://www.ietf.org/mailman/listinfo/dns-privacy
