DNS over HTTPS & DNS over TLS
Barry Leiba / Suzanne Woolf | ICANN67 | March 2020
| 1
Agenda
Overview of SAC1XX: Implications of DoH & DoT
Perspectives on DoH & DoT
Implications to the Namespace
1
2
4
5
Comparisons of the Technologies
3
Q & A
6
| 2
Security and Stability Advisory Committee (SSAC)
Who We Are
What We Do
What is Our Expertise
How We Advise
Role: Advise the ICANN community and Board on matters relating to the security and integrity of the Internet’s naming and address allocation systems.
108 Publications since 2002
| 3
| 3
Security and Stability Advisory Committee (SSAC)
ICANN’s Mission & Commitments
SSAC Publication Process
Consideration of SSAC Advice
(to the ICANN Board)
SSAC Submits Advice to ICANN Board
Board Acknowledges & Studies the Advice
Board Takes Formal Action on the Advice
1. Policy Development Process
3. Dissemination of Advice to Affected Parties
2. Staff Implementation with Public Consultation
4. Chose different solutions (explain why advice is not followed)
Publish
Form
Work Party
Review and Approve
Research and Writing
| 4
| 4
| 5
| 5
SAC1XX: Implications of DNS over HTTPS and DNS over TLS
| 6
SAC1XX: What NOT to expect
| 7
SAC1XX: Conclusions
| 8
Comparison of DNS over HTTPS and DNS over TLS
| 9
| 9
Three Technologies
| 10
Possible Traditional DNS Deployment
(green dashes show unencrypted paths)
| 11
Possible DNS over TLS Deployment in a Home Network
(red solids show encrypted paths)
| 12
Possible DNS over TLS Deployment in an Enterprise Network
| 13
Possible DNS over HTTPS Deployment
| 14
Different Perspectives on DNS over HTTPS and DNS over TLS
| 15
| 15
Parents
| 16
Enterprise Network Managers
| 17
Dissidents, Protesters, and Others
| 18
Internet Service Providers (ISPs)
| 19
Implications to the Namespace
| 20
| 20
Implications to the Namespace
| 21
Thank you
| 22
| 22