Re: draft-ietf-httpbis-rfc6265bis - preliminary questions for IETF dnsdir review

This may be helpful for context:
  https://httpwg.org/specs/rfc9110.html#authoritative.access

Cheers,


> On 25 Jan 2025, at 1:48 am, Petr Špaček <pspacek@isc.org> wrote:
> 
> Hello everyone.
> 
> I was assigned as the dnsdir reviewer for draft-ietf-httpbis-rfc6265bis.
> For more information about the DNS Directorate, please see
> https://wiki.ietf.org/en/group/dnsdir
> 
> I have a question before I start with real review:
> 
> What is the intended interaction with non-DNS naming systems?
> 
> I'm not an HTTP expert, but I would guess that anything in Name Service Switch equivalent on a given operating system will become entangled in the cookie Domain attribute business.
> 
> Just from top of my head
> - DNS
> - /etc/hosts equivalent
> - Tor onion.
> - GNUnet
> - NetBIOS
> - LLMNR
> - mDNS
> - (Let's not go any further...)
> 
> Yes, it is a mine field. I'm trying to find out how generic the name formatting text + security considerations should be because right now it mentions 'DNS' in couple places.
> 
> Thank you for your time.
> 
> -- 
> Petr Špaček

--
Mark Nottingham   https://www.mnot.net/

Received on Saturday, 25 January 2025 03:28:04 UTC