‹ Back
Deploy360 26 March 2017

[email protected], Day 1: IoT, IPv6, DNSSEC & TLS

Kevin Meynell
By Kevin MeynellSenior Manager, Technical and Operational Engagement

It’s a busy week IETF 98 in Chicago, and we’ll be bringing you daily blog posts that highlight what Deploy360 will be focused on during that day. And Monday is the busiest day, with a couple of working groups on the Internet-of-Things, along with sessions relevant to IPv6, DNSSEC and TLS.

The day kicks off at 09.00 CDT/UTC-6 with Homenet which is developing protocols for residential networks based on IPv6. This has one new draft up for discussion on a name resolution and service discovery architecture for homenets, but there’s been a lot of discussion recently about the recommendation to replace the use of  .home with .homenet as the default top-level name for local name resolution.

NOTE: If you are unable to attend IETF 98 in person, there are multiple ways to participate remotely.

Running in parallel is DMM that’s working on solutions to allow traffic to/from mobile nodes to take optimal routes, and has two IPv6-related items on the agenda. This includes an extension to the DHCPv6 protocol to support mobile hosts, and whether mobility extensions for ICMPv6 router advertisement messages are needed.

To complete the hectic morning is ACE which is developing authentication and authorization mechanisms for accessing resources on network nodes with limited CPU, memory and power.

In the afternoon, DNSOP is meeting from 13.00 CDT/UTC-6 and has a couple of items related to DNSSEC. One of these proposes a new mechanism for authenticated denial of existence, whilst the other proposes the use the BLAKE2 cryptographic hash function in NSEC3 responses. Some of the other items on the agenda such as DNS over TCP also have potential impacts on DNS security and privacy.

At the same time is T2TRG that investigates open research issues of how to turn IoT into reality, and is reporting on its recent activities.

Concluding the day is CURDLE during the evening session. This has published RFCs 8080 and 8103 since the last IETF, and this time will be focusing on the cryptographic aspects of PKIX, CMS and SSH.

For more background, please read the Rough Guide to IETF 98 from Olaf, Dan, Andrei, Mat, Karen and myself.

Relevant Working Groups

‹ Back

Disclaimer: Viewpoints expressed in this post are those of the author and may or may not reflect official Internet Society positions.

Related articles

Improving Technical Security 15 March 2019

DNS Privacy Frequently Asked Questions (FAQ)

We previously posted about how the DNS does not inherently employ any mechanisms to provide confidentiality for DNS transactions,...

Improving Technical Security 14 March 2019

Introduction to DNS Privacy

Almost every time we use an Internet application, it starts with a DNS (Domain Name System) transaction to map...

Improving Technical Security 13 March 2019

IPv6 Security for IPv4 Engineers

It is often argued that IPv4 practices should be forgotten when deploying IPv6, as after all IPv6 is a...

Join the conversation with Internet Society members around the world