[DNSOP] Re: Client authentication for encrypted DNS — interest check

Bill Woodcock <[email protected]> Sat, 11 Jul 2026 02:21:35 +0200
Newsgroups gmane.ietf.dnsop
Message-ID <[email protected]>

> On Jul 11, 2026, at 02:18, Aitor Santos <[email protected]> wrote:
> Transport-layer authentication within the TLS handshake is simpler and more robust — no tunnel management, no IP churn problem.
> The draft isn't trying to replace VPN — it's about the cases where VPN is operationally out of scope.

Exactly.  This isn’t what VPNs are for, this is what authentication is for.

This is why we don’t make everyone who uses email run their IMAP through a VPN, and everyone who uses the web run their HTTPS through a VPN.

                                -Bill

_______________________________________________
DNSOP mailing list -- [email protected]
To unsubscribe send an email to [email protected]
signature.asc (application/pgp-signature, 833 B)
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCAAdFiEEm6XJ0FdpKWJHso4lb6RwSyiLf4cFAmpRjI8ACgkQb6RwSyiL
f4cE3A//cBtW5ziUfAa+8rTNt6q6nq8E69LDlRXCzhMmlT4QkCkemzbG5vmuHxJf
0NMYhhVzAeITKuwh/4VEaR9eFUeJL4XhvVFChTJBufXiEJk5woo1i2e79Bu1ambU
dJ0ybhZHjHtNlkKaO/jdww38VGRldJ39IIa19wkBEOF0WSN4S1+uFvkH02g/54Fb
RPfuTz8oefj7VMXYdLLsdSKy0ZxLMwZspj1YNbB73c58qiT493lIIuzsKwUqRTvZ
j+HU9KGUW6OD2JSOD3V+SZkl6E94Ny+Rz6V/s5bV7YcA5XtDmoRJXIi7RYIOrOY6
2OBctOluiZOPDbf1Gj7SEFtYcGryLuzrdftpPxa64xWfjRyrMbpl3c1h67Fl/gbv
mtwVyove4ihSI1J3+apUac80dBSP8CzzqhqyIUiuYfVrLyXxl7r+fDyoxBpBDeEs
86OOfpCrkCo9E/xqEo99eawj5FJQPl+KZgpvuKX+X9ffU0fjwZAfz38PSKmK65De
rslA5mFXG3KvL9CFpF/lowSGDgfj6xDmbGNiPL2oV5sPMGC3gY0PcSwAtIzwGnji
MuylXHkov71T8KsOTNaeNQu2mFmXPfjmJWJjiCPIAMBuzdO6wyPB/oQuKJAU6bM2
uar1D/5Af9daUOId8e0hWt0ul4AqpfacRvYYPKp2RqdotNIKXCE=
=RNfK
-----END PGP SIGNATURE-----