Re: [dns-privacy] IETF 102 Agenda topics

2018-06-11 Thread Paul Hoffman

On 11 Jun 2018, at 9:24, Russ Housley wrote:

Given the large number of responses to the thread about DNS-over-TLS 
for recursive-to-authoritative, I would hope that this topic would 
have a significant part of the meeting. The biggest open topic is 
authentication of the server.


Should there be something in the server certificate that makes it 
clear that the server is an authoritative DNS server?  I do not think 
that an arbitrary Web PKI certificate is sufficient.  At a minimum, I 
think there should be an extended key usage in the certificate.


This would be a good discussion to have on a thread about the draft, not 
a thread about the agenda topics. :-)


--Paul Hoffman

___
dns-privacy mailing list
dns-privacy@ietf.org
https://www.ietf.org/mailman/listinfo/dns-privacy


Re: [dns-privacy] IETF 102 Agenda topics

2018-06-11 Thread Russ Housley
> Given the large number of responses to the thread about DNS-over-TLS for 
> recursive-to-authoritative, I would hope that this topic would have a 
> significant part of the meeting. The biggest open topic is authentication of 
> the server.

Should there be something in the server certificate that makes it clear that 
the server is an authoritative DNS server?  I do not think that an arbitrary 
Web PKI certificate is sufficient.  At a minimum, I think there should be an 
extended key usage in the certificate.

Russ

___
dns-privacy mailing list
dns-privacy@ietf.org
https://www.ietf.org/mailman/listinfo/dns-privacy


Re: [dns-privacy] IETF 102 Agenda topics

2018-06-11 Thread Paul Hoffman
Given the large number of responses to the thread about DNS-over-TLS for 
recursive-to-authoritative, I would hope that this topic would have a 
significant part of the meeting. The biggest open topic is 
authentication of the server.


--Paul Hoffman

___
dns-privacy mailing list
dns-privacy@ietf.org
https://www.ietf.org/mailman/listinfo/dns-privacy


[dns-privacy] IETF 102 Agenda topics

2018-06-11 Thread Brian Haberman
All,
 Tim & I have requested a 90-minute slot for DPRIVE at IETF 102 in
Montreal. This email is the first solicitation for agenda topics for
that meeting. If you would like to present in Montreal, please send the
chairs (dprive-cha...@ietf.org) your request with the following information:

* Topic or draft name
* Presenter name
* Amount of time requested
* Whether it will be a local or remote presentation

The chairs will prioritize the requests based on:

1. WG document/topic
2. Active discussion on mailing list
3. New topics

Regards,
Brian & Tim



signature.asc
Description: OpenPGP digital signature
___
dns-privacy mailing list
dns-privacy@ietf.org
https://www.ietf.org/mailman/listinfo/dns-privacy