A New Internet-Draft is available from the on-line Internet-Drafts directories.
This draft is a work item of the DNS PRIVate Exchange WG of the IETF.
Title : Recursive to Authoritative DNS with Encryption
Authors : Paul Hoffman
Peter van Dijk
Filename : draft-ietf-dprive-opportunistic-adotq-01.txt
Pages : 9
Date : 2021-02-22
Abstract:
This document describes a use case and a method for a DNS recursive
resolver to use either opportunistic encryption (that is, encryption
with optional authentication) or fully-authenticated encryption when
communicating with authoritative servers. The motivating use case
for this method is that more encryption on the Internet is better,
some resolver operators will only want to offer fully-authenticated
encryption when encryption is available, and some resolver operators
believe that opportunistic encryption is better than no encryption at
all. The method described here is optional for both the recursive
resolver and the authoritative server. This method supports both
fully-authenticate encryption and opportunistic encryption using the
same mechanism for discovery of encryption support and discovery of
authenticated public keys for the server.
IMPORTANT NOTE: This version of the document is completely different
than the earlier version. It now covers both opportunistic and
fully-authenticated encryption. It is in a very rough state, and
there are many holes in the description.
The IETF datatracker status page for this draft is:
https://datatracker.ietf.org/doc/draft-ietf-dprive-opportunistic-adotq/
There are also htmlized versions available at:
https://tools.ietf.org/html/draft-ietf-dprive-opportunistic-adotq-01
https://datatracker.ietf.org/doc/html/draft-ietf-dprive-opportunistic-adotq-01
A diff from the previous version is available at:
https://www.ietf.org/rfcdiff?url2=draft-ietf-dprive-opportunistic-adotq-01
Please note that it may take a couple of minutes from the time of submission
until the htmlized version and diff are available at tools.ietf.org.
Internet-Drafts are also available by anonymous FTP at:
ftp://ftp.ietf.org/internet-drafts/
_______________________________________________
dns-privacy mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/dns-privacy