The IESG has approved the following document: - 'Structured Error Data for Filtered DNS' (draft-ietf-dnsop-structured-dns-error-26.txt) as Proposed Standard
This document is the product of the Domain Name System Operations Working Group. The IESG contact persons are Mahesh Jethanandani, Éric Vyncke and Mohamed Boucadair. A URL of this Internet-Draft is: https://datatracker.ietf.org/doc/draft-ietf-dnsop-structured-dns-error/ # Technical Summary DNS filtering is widely deployed for various reasons, including network security. However, filtered DNS responses lack structured information for end users to understand the reason for the filtering. Existing mechanisms to provide explanatory details to end users cause harm especially if the blocked DNS response is for HTTPS resources. This document updates RFC 8914 by signaling client support for structuring the EXTRA-TEXT field of the Extended DNS Error to provide details on the DNS filtering. Such details can be parsed by the client and displayed, logged, or used for other purposes. # Working Group Summary ##From the shepherd's write-up: Initially, in 2020, the draft encountered substantial objections within the DNSOP Working Group. The authors iteratively improved the document based on feedback from WG discussions, and over time it gained support from several industry stakeholders. Following the first Working Group Last Call (WGLC), the WG concluded that consensus had been reached. However, during IETF Last Call, concerns were raised by participants from the Security Area, as well as potential misalignment with the related draft draft-nottingham-dnsop-censorship-transparency. The draft was therefore returned to the DNSOP Working Group, and a virtual interim meeting was held to address the feedback and alignment issues. This led to further revisions and a second, extended WGLC, during which constructive discussion resulted in additional improvements to the document. ## AD additional notes There are some disagreement on the usefulness of the human-readable string as it seems that browsers will never display a string received over such a channel. Document Quality ## From shepherd's write-up As part of the protocol design, a proof-of-concept implementation and demo were presented by Gianpaolo Scalone and Ralf Weber during the DNSOP WG sessions at IETF 116. Several vendors have since indicated their intention to implement the standard in their products, and operators have expressed interest in deploying it within their network services. Following the virtual interim and second WGLC, the document received thorough DNS Directorate review, as well as additional input from participants who had raised concerns during IETF Last Call. The document has been updated accordingly and there are no conflicts between other ongoing related work. # Personnel The Document Shepherd for this document is Benno Overeinder. The Responsible Area Director is Éric Vyncke. # IANA Note The IANA has already reviewed the draft and is interacting with the authors. _______________________________________________ IETF-Announce mailing list -- [email protected] To unsubscribe send an email to [email protected]
