Re: [dns-privacy] New draft on encrypting the stub-to-resolver link: draft-hoffman-dns-tls-stub-00.txt

Wes Hardaker <wjhns1@hardakers.net> Fri, 29 August 2014 12:26 UTC

Return-Path: <wjhns1@hardakers.net>
X-Original-To: dns-privacy@ietfa.amsl.com
Delivered-To: dns-privacy@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id E7EB31A0188 for <dns-privacy@ietfa.amsl.com>; Fri, 29 Aug 2014 05:26:24 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -3.269
X-Spam-Level:
X-Spam-Status: No, score=-3.269 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_LOW=-0.7, RP_MATCHES_RCVD=-0.668, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id pcBOGrp7LYiA for <dns-privacy@ietfa.amsl.com>; Fri, 29 Aug 2014 05:26:22 -0700 (PDT)
Received: from mail.hardakers.net (mail.hardakers.net [168.150.236.43]) by ietfa.amsl.com (Postfix) with ESMTP id ACC941A0031 for <dns-privacy@ietf.org>; Fri, 29 Aug 2014 05:26:22 -0700 (PDT)
Received: from localhost (wjh.hardakers.net [10.0.0.2]) by mail.hardakers.net (Postfix) with ESMTPSA id EB6C528BB2; Fri, 29 Aug 2014 05:26:21 -0700 (PDT)
From: Wes Hardaker <wjhns1@hardakers.net>
To: Mark Andrews <marka@isc.org>
References: <20140818175701.12317.96810.idtracker@ietfa.amsl.com> <FF99C324-2959-48EB-A187-18007F7AA364@vpnc.org> <814D0BFB77D95844A01CA29B44CBF8A7A27F3E@lhreml513-mbb.china.huawei.com> <alpine.LFD.2.10.1408191033210.19423@bofh.nohats.ca> <814D0BFB77D95844A01CA29B44CBF8A7A27FBE@lhreml513-mbb.china.huawei.com> <alpine.LFD.2.10.1408191159190.19423@bofh.nohats.ca> <814D0BFB77D95844A01CA29B44CBF8A7A280CF@lhreml513-mbb.china.huawei.com> <86mwb0e5pd.fsf@strotmann.de> <0l61hdogv2.fsf@wjh.hardakers.net> <20140828022601.E63EE1DA773E@rock.dv.isc.org>
Date: Fri, 29 Aug 2014 05:26:21 -0700
In-Reply-To: <20140828022601.E63EE1DA773E@rock.dv.isc.org> (Mark Andrews's message of "Thu, 28 Aug 2014 12:26:01 +1000")
Message-ID: <0l38cflbwy.fsf@wjh.hardakers.net>
User-Agent: Gnus/5.130012 (Ma Gnus v0.12) Emacs/24.3 (gnu/linux)
MIME-Version: 1.0
Content-Type: text/plain
Archived-At: http://mailarchive.ietf.org/arch/msg/dns-privacy/9s5rBipGfnAA6KlTX_plNRbOV2g
Cc: Carsten Strotmann <cas@strotmann.de>, Hosnieh Rafiee <hosnieh.rafiee@huawei.com>, "dns-privacy@ietf.org" <dns-privacy@ietf.org>, Paul Wouters <paul@nohats.ca>, Wes Hardaker <wjhns1@hardakers.net>
Subject: Re: [dns-privacy] New draft on encrypting the stub-to-resolver link: draft-hoffman-dns-tls-stub-00.txt
X-BeenThere: dns-privacy@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: <dns-privacy.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dns-privacy>, <mailto:dns-privacy-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/dns-privacy/>
List-Post: <mailto:dns-privacy@ietf.org>
List-Help: <mailto:dns-privacy-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dns-privacy>, <mailto:dns-privacy-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 29 Aug 2014 12:26:25 -0000

Mark Andrews <marka@isc.org> writes:

> Actually DNSSEC could give you the key of the resolver securely
> provided it has a public address.  Publish a KEY record signed in
> the DNS under in-addr.arpa or ip6.arpa.  If need to we define flag
> bits to say it is for this purpose.  For private addresses you need
> to have a trust anchor for the private part of the reverse tree or
> use leap of faith.

Yes, that's what I was saying...  I was just following it by "there are
a huge number of private-address resolvers in the real world".

-- 
Wes Hardaker
Parsons