[dd] Downgrade attack on legacy resolvers and DELEG only delegations
Roy Arends <roy@dnss.ec> Sat, 10 February 2024 23:16 UTC
Return-Path: <roy@dnss.ec>
X-Original-To: dd@ietfa.amsl.com
Delivered-To: dd@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id DA847C14F602 for <dd@ietfa.amsl.com>; Sat, 10 Feb 2024 15:16:13 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -7.106
X-Spam-Level:
X-Spam-Status: No, score=-7.106 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_HI=-5, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=dnss.ec
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id moaaq-g-V4FA for <dd@ietfa.amsl.com>; Sat, 10 Feb 2024 15:16:07 -0800 (PST)
Received: from mail-pg1-x530.google.com (mail-pg1-x530.google.com [IPv6:2607:f8b0:4864:20::530]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id D6E81C14E513 for <dd@ietf.org>; Sat, 10 Feb 2024 15:16:06 -0800 (PST)
Received: by mail-pg1-x530.google.com with SMTP id 41be03b00d2f7-5ceb3fe708eso1466346a12.3 for <dd@ietf.org>; Sat, 10 Feb 2024 15:16:06 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=dnss.ec; s=google; t=1707606965; x=1708211765; darn=ietf.org; h=to:message-id:subject:date:mime-version:content-transfer-encoding :from:from:to:cc:subject:date:message-id:reply-to; bh=6yJEl1wQUvn5jyyAwmQNDS6k8JoAR+emLqeMqXiTQz0=; b=DH40stsaXBRWcbxwjTx6PUTL0a2PCXac5xCwWFvIa5lenlfGboACllteAQcp2SWrwx qHSh1fNT/m7/1ULde2LYGEKxdXqSeslisCl3GUnrMS5wSswm6bmgefP4RhFb1Kob/boW o0pXQbWBjam7az5LL8F8RMIYFchBDl/8veEiM=
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1707606965; x=1708211765; h=to:message-id:subject:date:mime-version:content-transfer-encoding :from:x-gm-message-state:from:to:cc:subject:date:message-id:reply-to; bh=6yJEl1wQUvn5jyyAwmQNDS6k8JoAR+emLqeMqXiTQz0=; b=Ud8X+Yskp9CMExbQCcAbiNHgSNZRMrUQvciw4p7tpvxJFhBfNqqzSZ2/z0Y180zbdh kb5dCbNeR298Gks7CpolRvq1LKzczY4zmIj+ZXl1kG0lHlPn9TJsP9bh2yIMty7li9zO CdmgzkEfxb3LYXcD8truaa8TnaTvuvvTnl/BNb0AjLhBSm1N1VZV3CSQeh2qmUBCCxlJ 5MP0Cj5Te+fo/NhFtUHMFh8G0N6j5jmSFN2J3KUM+NrRrVP6WSC6uS8rTF4K9lYTaUaf sS+SoDn/9bmGngLdNQWwbYQMwJOQDKMnOLtbLTOXXayyOg44S6Kv/PxReofXP+rpSULn 8j9g==
X-Gm-Message-State: AOJu0YzsbQbMih5mKRddqFL0oYLPH4BidFzCxcJ0SuZSpNhSKwoizTST YqiLhtQtkV8DK4Ter+jXKxsMTcfR9174A0l7llLz7SSHxsm+WTuJPVGbQ2uKxyu+GXujXM9mVg5 QHLQ=
X-Google-Smtp-Source: AGHT+IFg6FSrAWuq4KughyMAKNAUOJH0hJTYsqFyposMntDtU3/a62sy7v/pNKoa2eP2ItUq2DSpvg==
X-Received: by 2002:a17:902:ec88:b0:1da:16ef:63d6 with SMTP id x8-20020a170902ec8800b001da16ef63d6mr3912833plg.9.1707606965416; Sat, 10 Feb 2024 15:16:05 -0800 (PST)
X-Forwarded-Encrypted: i=1; AJvYcCUUYiDXtrsdMH5Hi1Aae5UpLymn6emRXhLdav3/aViaD9V/L/BENgo+T4S9UOA2KHCgdBO6s15QnhTNOg==
Received: from smtpclient.apple ([78.111.198.85]) by smtp.gmail.com with ESMTPSA id kz6-20020a170902f9c600b001d9a91af8a4sm3533515plb.28.2024.02.10.15.16.04 (version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128); Sat, 10 Feb 2024 15:16:05 -0800 (PST)
From: Roy Arends <roy@dnss.ec>
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
Mime-Version: 1.0 (Mac OS X Mail 16.0 \(3774.400.31\))
Date: Sat, 10 Feb 2024 23:15:51 +0000
Message-Id: <0FBAD068-46A3-4ECC-99BF-A5F6F577FB73@dnss.ec>
To: dd@ietf.org
X-Mailer: Apple Mail (2.3774.400.31)
Archived-At: <https://mailarchive.ietf.org/arch/msg/dd/4kajcXMRO3FcAk9kuBQLShAocTY>
Subject: [dd] Downgrade attack on legacy resolvers and DELEG only delegations
X-BeenThere: dd@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: DNS Delegation <dd.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dd>, <mailto:dd-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dd/>
List-Post: <mailto:dd@ietf.org>
List-Help: <mailto:dd-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dd>, <mailto:dd-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sat, 10 Feb 2024 23:16:13 -0000
The following situation requires proper handling: In a pathological case, an adversary has the ability to replay an authenticated denial record that exists at a DELEG-only delegation (note that the NS Type Bit in the Type Bit Maps is not set) to a legacy resolver/validator. In this replay, the RCODE is altered from NOERROR to NXDOMAIN. It's evident that the delegation is present, as indicated by the DELEG record, but its existence can be falsely negated. In the typical case, the legacy resolver lacks understanding of DELEG and cannot pursue the delegation. It's important to note that this inability to follow the delegation results in a failure scenario (SERVFAIL) that is distinct from an NXDOMAIN response. Warmly, Roy
- [dd] Downgrade attack on legacy resolvers and DEL… Roy Arends
- Re: [dd] [Ext] Downgrade attack on legacy resolve… Edward Lewis