IETF-751 Olafur Gudmundsson Andrew Sullivan.

Slides:



Advertisements
Similar presentations
IETF Calsify.
Advertisements

Transport Layer Security (TLS) IETF-76 Chairs Joe Salowey Eric Rescorla
Secure Telephone Identity Revisited STIR IETF 88.
OAuth 2.0 Security IETF OAuth WG Conference Call, 14th December 2012.
L2VPN WG “NVO3” Meeting IETF 82 Taipei, Taiwan. Agenda Administrivia Framing Today’s Discussions (5 minutes) Cloud Networking: Framework and VPN Applicability.
Note Well Any submission to the IETF intended by the Contributor for publication as all or part of an IETF Internet-Draft or RFC and any statement made.
PPSP Working Group IETF-89 London, UK 16:10-18:40, Tuesday, Webex: participation.html.
CCAMP Working Group Online Agenda and Slides at: Tools start page:
IETF 90: NetExt WG Meeting. Note Well Any submission to the IETF intended by the Contributor for publication as all or part of an IETF Internet- Draft.
IETF-89 AQM WG Wesley Eddy Richard Scheffenegger
L3VPN WG IETF 78 09/11/ :00-15:00 Chairs: Marshall Eubanks Danny McPherson Ben Niven-Jenkins.
BLISS – IETF 71 Jason Fischl Shida Schubert
SIPCLF Working Group Spencer Dawkins Theo Zourzouvillys IETF 76 – November 2009 Hiroshima, Japan.
Transport Layer Security (TLS) IETF-72, Dublin July 27, 2008 Chairs: Eric Rescorla Joseph Salowey.
EAP Method Update (EMU) IETF-79 Chairs Joe Salowey Alan DeKok.
1 NOTE WELL Any submission to the IETF intended by the Contributor for publication as all or part of an IETF Internet-Draft or RFC and any statement made.
GROW IETF 78 Maastricht, Netherlands. Note Well Any submission to the IETF intended by the Contributor for publication as all or part of an IETF Internet-Draft.
IETF 86 PIM wg meeting. Note Well Any submission to the IETF intended by the Contributor for publication as all or part of an IETF Internet-Draft or RFC.
IETF 79 - Beijing, China1 Martini Working Group IETF 79 Beijing Chairs: Bernard Spencer
BEHAVE Working Group IETF 81 – Quebec City July 2011 Chairs: Dave Thaler, Dan Wing, 1.
Extensible Messaging and Presence Protocol (XMPP) WG Interim Meeting, Monday, January 7,
IPPM WG IETF 79. Note Well Any submission to the IETF intended by the Contributor for publication as all or part of an IETF Internet-Draft or RFC and.
Tictoc working group Thursday, 28 July – 1720 EDT (1920 – 2120 UTC) Karen O’Donoghue and Yaakov Stein, co-chairs.
Technical Plenary Agenda IETF 81 Quebec City, Quebec July 25, 2011 Presentations: Jabber room:
SIPREC WG, IETF# , GMT+2 John Elwell (WG co-chair) Brian Rosen (WG co-chair)
CCAMP Working Group Online Agenda and Slides at: Data tracker:
Web Authorization Protocol (oauth) Hannes Tschofenig.
Transport Service (TAPS) Aaron Falk
CLUE WG IETF-83 Mary Barnes (WG co-chair) Paul Kyzivat (WG co-chair)
BFD IETF 83. Note Well Any submission to the IETF intended by the Contributor for publication as all or part of an IETF Internet-Draft or RFC and any.
Mary Barnes (WG co-chair) Cullen Jennings (WG co-chair) DISPATCH WG IETF 90.
OAuth WG Blaine Cook, Hannes Tschofenig. Note Well Any submission to the IETF intended by the Contributor for publication as all or part of an IETF Internet-Draft.
Authentication and Authorization for Constrained Environment (ACE) WG Chairs: Kepeng Li, Hannes
IETF 89, LONDON, UK LISP Working Group. 2 Agenda and slides:  lisp.html Audio Stream 
SPFBIS IETF 83 Paris, France SPFBIS -- IETF 831. Agenda 1.Administivia 2.RFC 4408 issues 3.SPF RRTYPE (issue 9) 4.DNS amplification attacks (issue 24)
IETF – NVO3 WG Virtual Interim Meeting Chairs: Secretary: Sam Aldrin Benson Schliesser Matthew Bocci.
DNSEXT at IETF-83 Paris 2012/3/27 at 17:10 – 18:10 Ólafur Guðmundsson Andrew Sullivan.
DMM WG IETF 84 DMM WG Agenda & Status Tuesday, July 31 st, 2012 Jouni Korhonen, Julien Laganier.
Transport Layer Security (TLS) IETF-84 Chairs: Eric Rescorla Joe Salowey.
Interface to the Routing System (IRS) BOF IETF 85, Atlanta November 2012.
IPR WG IETF 62 Minneapolis. IPR WG: Administrivia Blue sheets Scribes Use the microphones Note Well.
IETF #81 - NETCONF WG session 1 NETCONF WG IETF 81, Quebec City, Canada MONDAY, July 25, Bert Wijnen Mehmet Ersue.
Transport Layer Security (TLS) IETF 73 Thursday, November Chairs: Eric Rescorla Joe Salowey.
IETF #73 - NETMOD WG session1 NETMOD WG IETF 73, Minneapolis, MN, USA November 20, David Harrington David Partain.
Transport Layer Security (TLS) IETF-78 Chairs Joe Salowey Eric Rescorla
HIP WG Gonzalo Camarillo David Ward IETF 80, Prague, Czech Republic THURSDAY, March 31, 2011, Barcelona/Berlin.
OPSREA Open Meeting Area Directors: Dan Romascanu and Ron Bonica Monday, March 28, 2011 Morning Session, 10:30 – 11:30, Room Barcelona/Berlin Discussion.
Agenda Behcet Sarikaya Dirk von Hugo November 2012 FMC BOF IETF
1 Yet Another Mail Working Group IETF 76 November 11, 2009.
IETF #82 - NETCONF WG session 1 NETCONF WG IETF 82, Taipei, Taiwan TUESDAY, November 15, Afternoon Session III Bert Wijnen Mehmet Ersue.
Opsawg chairs Scott Bradner Chris Liljenstolpe. Note Well Any submission to the IETF intended by the Contributor for publication as all or part of an.
NETWORK-BASED MOBILITY EXTENSIONS WG (NETEXT) July 28 th, 2011 IETF81 1.
Agenda Stig Venaas Behcet Sarikaya November 2011 Multimob WG IETF
Pseudowire And LDP-enabled Services (PALS) WG Status IETF-92 Dallas Co-Chairs: Stewart Bryant and Andy Malis
Alternatives to Content Classification for Operator Resource Deployment (ACCORD) BOF Chairs: Gonzalo Camarillo & Pete Resnick.
TSVAREA IETF84 - Vancouver. Note Well Any submission to the IETF intended by the Contributor for publication as all or part of an IETF Internet-Draft.
OPSAWG chairs: Scott Bradner Christopher Liljenstolpe.
Agenda Wednesday, July 29, :00 – 15:00 Congresshall B Please join the Jabber room: LEDBAT WG IETF 75.
STIR Secure Telephone Identity Revisited
NOTE WELL Any submission to the IETF intended by the Contributor for publication as all or part of an IETF Internet-Draft or RFC and any statement made.
Note Well Any submission to the IETF intended by the Contributor for publication as all or part of an IETF Internet-Draft or RFC and any statement made.
MODERN Working Group IETF 97 November 14, 2016.
SPRING IETF-98 Tuesday, March 28.
Note Well Any submission to the IETF intended by the Contributor for publication as all or part of an IETF Internet-Draft or RFC and any statement made.
Thursday, 20th of July 2017.
16th November 2016 Gorry Fairhurst (via webrtc) David Black WG chairs
Note Well Any submission to the IETF intended by the Contributor for publication as all or part of an IETF Internet-Draft or RFC and any statement made.
TEAS CCAMP MPLS PCE Working Groups
SIPBRANDY Chair Slides
Scott Bradner & Martin Thomson
Presentation transcript:

IETF-751 Olafur Gudmundsson Andrew Sullivan

IETF-752 Note Well Any submission to the IETF intended by the Contributor for publication as all or part of an IETF Internet-Draft or RFC and any statement made within the context of an IETF activity is considered an "IETF Contribution". Such statements include oral statements in IETF sessions, as well as written and electronic communications made at any time or place, which are addressed to: The IETF plenary session The IESG, or any member thereof on behalf of the IESG Any IETF mailing list, including the IETF list itself, any working group or design team list, or any other list functioning under IETF auspices Any IETF working group or portion thereof The IAB or any member thereof on behalf of the IAB The RFC Editor or the Internet-Drafts function All IETF Contributions are subject to the rules of RFC 5378 and RFC 3979 (updated by RFC 4879). Statements made outside of an IETF session, mailing list or other function, that are clearly not intended to be input to an IETF activity, group or function, are not IETF Contributions in the context of this notice. Please consult RFC 5378 and RFC 3979 for details. A participant in any IETF activity is deemed to accept all IETF rules of process, as documented in Best Current Practices RFCs and IESG Statements. A participant in any IETF activity acknowledges that written, audio and video records of meetings may be made and may be available to the public.

IETF-753 Forgery Resilience #2.5: Path forward Olafur Gudmundsson Andrew Sullivan

IETF-754 History RFC5452 –Adopted early 2007 –Issued Jan 2009 –Addresses how to add entropy to queries via “standards-compliant” means Mid 2008 word of Kaminsky attack causes lots of mailing list traffic and panic. –DNSEXT starts process to figure out if/what to do for more FR measures –Good uptake in new “hardened” resolver versions. Fall 2008 IETF-73 design team meets and suggests path forward –Nothing happens.

IETF-755 Topic: Additional Entropy Additional Entropy: –DNS Ping:  ”just do it” helps when available, does not hurt in any case  Withdrawn –0x20: helps in the case when DNS Ping is not available,  “Mostly harmless” the only standards actions: specify that server MUST copy QName unchanged into answer and resolver MUST strip 0x20 from answer. –“RTT Banding” or “Name server scatter”: Requires much more work before we can recommend on how to do this, at least a document on how to measure and maintain measures off Round Trip times should be written. i.e. a RTT BCP  Discourage for now

IETF-756 Topic: Data Acceptance Cache overwrite  recommend against –At same credibility: –Extend TTL’s: CNAME and DNAME chains: –  Recommend recursive resolvers perform the full chain processing, i.e. only accept first [CD]NAME from each answer. Fetch better data: –Some attacks rely on caches to overwrite existing data with newer data at same criticality, this can be prevented by explicitly asking authority for the data that is included in referrals. –Implications: more queries, may cause outages due to errors that are currently masked  Needs more study before recommendation

IETF-757 Topic: Query Fallback TCP –  Should be avoided as much as possible –Study if current OS’s can be tuned to handle the load ORG survives with 15% of queries via TCP

IETF-758 Documents draft-barwood-dnsext-fr-resolver- mitigations-08 draft-wijngaards-dnsext-resolver-side- mitigation-01 Pick one or none ?

IETF-759 Next steps: Open Microphone

IETF-7510 EDNS0 at IETF-75 EDNS0bis-02 –New editor: Michael Graff –Big changes read and comment –Document Goals error handling Size fall back Close bit label registry Mandate ENDS0 support Clarify language Change allocation process for new options ? –Finish this year

IETF-7511 ENDS0 size and DO New version 01 yesterday Main change: If size < 1220 && DO == 1 –clear DO bit in answer and treat as no DO –OR RCODE=FORMERR & OPT RR included –Reason simplify processing and tell requestor that ENDS0 is understood but query is inconsistent.

IETF-7512 EDNS0 size discovery

IETF-7513 Behave DNS64

IETF-7514 IXFR-ONLY

IETF-7515 Charter What to add ? –IXFR-ONLY ? –DNS RFC GUIDE ? –RFC1034/5 rewrite ? –DNSKEY support option ? Will ask mailing list for quick feedback

IETF-7516 IPv4 + IPv6 query

IETF-7517 DNSSEC key algorithms Dr. Crocker: – DNSSEC Algorithm signal David Conrad on RSA/SHA256 in root

IETF-7518 DNSSEC algorithm maintenance policies