IETF DNSOP WG Update – and some DPRIVE

Slides:



Advertisements
Similar presentations
© 2006 NEC Corporation - Confidential age 1 November SPEERMINT Security Threats and Suggested Countermeasures draft-ietf-speermint-voipthreats-01.
Advertisements

EDNS0 Client-Subnet for DNS based CDNs
IETF-751 Olafur Gudmundsson Andrew Sullivan.
1IETF59 DNSOP WG IPv6 DNS Discovery Issues Jaehoon Paul Jeong ETRI 1st March th IETF – Seoul,
SIP working group status Keith Drage, Dean Willis.
MPTCP – Multipath TCP WG Meeting Toronto, IETF-90, 21 st July 2014 Philip Eardley Yoshifumi Nishida 1.
© 1998 R. Gemmell IETF WG Presentation1 Robert Gemmell ROAMOPS Working Group.
DIME WG IETF 82 Dime WG Agenda & Status THURSDAY, November 17, 2011 Jouni Korhonen & Lionel Morand.
1 DHCP Authentication Discussion INTAREA meeting, 70th IETF Vancouver, Canada Jari Arkko and Ralph Droms.
MPTCP – MULTIPATH TCP Interim meeting #3 20 th October 2011 audio Yoshifumi Nishida Philip Eardley.
IETF – ECRIT Emergency Context Resolution using Internet Technologies ESW 5 – Vienna October 2008 Marc Linsner.
XCON WG IETF-73 Meeting Instant Messaging Sessions with a Centralized Conferencing (XCON) System draft-boulton-xcon-session-chat-02 Authors: Chris Boulton.
What makes for a quality RFC? An invited talk to the MPLS WG Adrian Farrel IETF-89 London, March 2014.
IETF #91 OAuth Meeting Derek Atkins Hannes Tschofenig.
Working Group #4: Network Security Best Practices September 12, 2012 Presenter: Rod Rasmussen, Internet Identity WG #4 Co-Chair.
SHIM6 Protocol Drafts Overview Geoff Huston, Marcelo Bagnulo, Erik Nordmark.
DNS Privacy Overview Allison Mankin & Shumon Huque, Verisign Labs DNS-OARC Fall Workshop October 3, 2015.
Forgery Resilience Phase #2 Ólafur Guðmundsson
Guidance for Running Multiple IPv6 Prefixes (draft-liu-v6ops-running-multiple-prefixes-02) Bing Liu, Sheng Jiang (Speaker), Yang Bo IETF91
A study of caching behavior with respect to root server TTLs Matthew Thomas, Duane Wessels October 3 rd, 2015.
Peer to Peer Streaming Protocol (PPSP) BOF Gonzalo Camarillo Ericsson Yunfei Zhang China Mobile IETF76, Hiroshima, Japan 13:00~15:00 THURSDAY, Nov 12,
1 CMPT 471 Networking II DNS © Janice Regan,
1 Brian Hartvigsen Manager, Site Reliability Engineering Real World Impacts of EDNS Client Subnet.
Diameter Overload DIME WG IETF 87 July, Starting Point DIAMETER_TOO_BUSY provides little guidance on what a Diameter client should do when it receives.
Slide title In CAPITALS 50 pt Slide subtitle 32 pt RTSP draft-ietf-mmusic-rfc2396bis-10 Magnus Westerlund Co-auhtors: Henning Schulzrinne, Rob Lanphier,
Requirements and Selection Process for RADIUS Crypto-Agility December 5, 2007 David B. Nelson IETF 70 Vancouver, BC.
March 20th, 2001 SIP WG meeting 50th IETF SIP WG meeting Overlap signalling handling
Subject Identification Method August, 2004 Tim Polk, NIST.
Trust Anchor Update Requirements for DNSSEC Russ Mundy for the editors Steve Crocker, Howard Eland, Russ Mundy.
John S. Otto Mario A. Sánchez John P. Rula Fabián E. Bustamante Northwestern, EECS.
The Internet Engineering Task Force Security Area Kathleen Moriarty Stephen Farrell Security Area Directors.
Dhc WG 3/2/2004, IETF 59, Seoul. 3/2/2004dhc WG - IETF 59, Seoul2 Agenda Administrivia, Agenda bashing Ralph Droms 05 minutes DHCP Option for Proxy Server.
PMIPv6 multicast handover optimization by the Subscription Information Acquisition through the LMA (SIAL) Luis M. Contreras Telefónica I+D Carlos J. Bernardos.
DOTS Requirements Andrew Mortensen November 2015 IETF 94 1.
Source Packet Routing in Networking WG (spring) IETF 89 – London Chairs: John Scudder Alvaro Retana
Using Digital Signature with DNS. DNS structure Virtually every application uses the Domain Name System (DNS). DNS database maps: –Name to IP address.
Host Identifier Revocation in HIP draft-irtf-hiprg-revocation-01 Dacheng Zhang IETF 79.
DNS/DNSSEC/DPRIV E IETF 96 Hackathon Problem Solved – DNS security and privacy enhancements and interoperabilty Method of Solution – multiple user stories,
CLUE WG Interim Meeting San Jose, CA Sept , 2012
So You Inherited a DNS Server…
Open issues with PANA Protocol
DNS Team IETF 99 Hackathon.
dnssd WG Chairs: Ralph Droms,
CLUE WG Interim Meeting San Jose, CA Sept , 2012
draft-ietf-simple-message-sessions-00 Ben Campbell
CS 5565 Network Architecture and Protocols
DNS Privacy: Problem and solutions
Living on the Edge: (Re)focus DNS Efforts on the End-Points
Teemu Savolainen (Nokia) MIF WG IETF#75 28-July-2009
IETF 86 Orlando MBONED.
RFC 7706: Decreasing Access Time to Root Servers by Running One on Loopback A good idea or not? Petr Špaček • •
draft-dharini-ccamp-dwdm-if-param-yang-00
A Speculation on DNS DDOS
DNSSEC Basics, Risks and Benefits
Working at a Small-to-Medium Business or ISP – Chapter 7
Application Lifecycle Management – Best Practices for SharePoint and Office App development November 2015.
IETF 84 Vancouver, BC, CA Wednesday, 1 Aug 2012
.edu DNSSEC Testbed Lessons Learned
IETF68 Mini-BOF MIB-Doctor-Sponsored MIB Document Templates
Migration-Issues-xx Where it’s been and might be going
dnssd WG Chairs: Ralph Droms,
ECN Experimentation draft-black-ecn-experimentation
David Noveck IETF99 at Prague July 20, 2017
“DNS Flag day” A tale of five ccTLDs Hugo Salgado, .CL
What makes for a quality RFC?
Content Delivery and Remote DNS services
was not invented by Al Gore…
IETF-104 (Prague) DHC WG Next steps
IETF 87 DHC WG Berlin, Germany Thursday, 1 August, 2013
Neda Kianpour - Lead Network Engineer - Salesforce
Presentation transcript:

IETF DNSOP WG Update – and some DPRIVE Suzanne Woolf Tim Wicinski Benno Overeinder

IETF DNSOP Update on … (1) Submitted to IESG for publication draft-ietf-dnsop-attrleaf /draft-ietf-dnsop-attrleaf-fix draft-ietf-dnsop-dns-capture-format draft-ietf-dnsop-isp-ip6rdns draft-ietf-dnsop-kskroll-sentinel draft-ietf-dnsop-refuse-any draft-ietf-dnsop-session-signal draft-ietf-dnsop-terminology-bis … and happy OPS AD

IETF DNSOP Update on … (2) IESG document process

… or Signposting for Operator Input

Provisioning and Multi Provider (1) Aliasing/redirecting in DNS solution for website hosted by CDNs amongst others (www.example.com vs. example.com) ANAME and recently a minimal ANAME (Evan Hunt, Peter van Dijk, and Tony Finch are in the room) CNAME in apex draft and presentation by Ondřej Surý at OARC 29 (in the room; Petr Špaček started discussion in DNSOP) also discusses CNAME+DNAME and SRV

Provisioning and Multi Provider (2) Multi provider DNSSEC models deploying DNSSEC in multiple DNS providers setup to distribute an authoritative DNS service (Shumon Huque, John Dickinson, and Jan Vcelak are in the room) Two main models described: (i) serve only and (ii) sign and server

Serving Stale Data to Improve DNS Resiliency draft-tale-dnsop-serve-stale, authors Dave Lawrence and Warren Kumari (both in the room) and Puneet Sood use stale DNS data to avoid outages when authoritative nameservers cannot be reached to refresh expired data IPR statements by Akamai and Google Implementations exist: Akamai, Knot Resolver, OpenDNS, and Unbound Measurements of serving stale data Giovane Moura, When Dike Breaks

WG Last Call: Algorithm Update Algorithm Implementation Requirements and Usage Guidance for DNSSEC, draft-ietf-dnsop-algorithm-update (Ondřej Surý and Paul Wouters) specify a set of algorithm implementation requirements and usage guidelines to ensure that there is at least one algorithm that all implementations support

The Back of the Camel and Code Complexity –a personal perspective– (New) IETF DNS standards add complexity “We do have the sense that the discussion in London really resonated with people, and a couple of the ideas out if it seem to be continuing as part of the discussion in DNSOP — that we should think about complexity in the protocol, and pay attention to who’s implementing things and why. We know that over the long term, wrestling with these issues is part of how we keep a successful protocol evolving in a useful way.” DNS software implementors Work arounds for broken software DNS flag day

DPRIVE Recharter Develop requirements for adding confidentiality to DNS exchanges between recursive resolvers and authoritative servers (unpublished document). Investigate potential solutions for adding confidentiality to DNS exchanges involving authoritative servers (Experimental). Define, collect and publish performance data measuring effectiveness of DPRIVE-published technologies against pervasive monitoring attacks. Document Best Current Practices for operating DNS Privacy services.

Q&A