Return-Path: <yaojk@cnnic.cn>
X-Original-To: dnsext@ietfa.amsl.com
Delivered-To: dnsext@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com
 (Postfix) with ESMTP id 479D21A1F7B for <dnsext@ietfa.amsl.com>;
 Tue, 19 Nov 2013 22:59:53 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.424
X-Spam-Level: 
X-Spam-Status: No,
 score=-2.424 tagged_above=-999 required=5 tests=[BAYES_00=-1.9,
 HTML_MESSAGE=0.001, RP_MATCHES_RCVD=-0.525] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com
 [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id s6aolX7HZjan for
 <dnsext@ietfa.amsl.com>; Tue, 19 Nov 2013 22:59:51 -0800 (PST)
Received: from cnnic.cn (smtp.cnnic.cn [218.241.118.7]) by ietfa.amsl.com
 (Postfix) with SMTP id 3AC871A1F76 for <dnsext@ietf.org>;
 Tue, 19 Nov 2013 22:59:50 -0800 (PST)
X-EYOUMAIL-SMTPAUTH: yaojk@cnnic.cn
Received: from unknown127.0.0.1 (HELO healthyao-think) (127.0.0.1) by
 127.0.0.1 with SMTP; Wed, 20 Nov 2013 14:59:39 +0800
Date: Wed, 20 Nov 2013 14:59:40 +0800
From: "Jiankang Yao" <yaojk@cnnic.cn>
To: "Ted Lemon" <ted.lemon@nominum.com>,
 "dnsext@ietf.org Group" <dnsext@ietf.org>
References: <CFD6B510-D70E-4308-BF3E-B2E7C2ADCBEB@nominum.com>
X-Priority: 3
X-Has-Attach: no
X-Mailer: Foxmail 7.0.1.92[cn]
Mime-Version: 1.0
Message-ID: <201311201459364160303@cnnic.cn>
Content-Type: multipart/alternative;
 boundary="----=_001_NextPart011677867318_=----"
Subject: Re: [dnsext] Authenticated denial of existence...
X-BeenThere: dnsext@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
Reply-To: yaojk <yaojk@cnnic.cn>
List-Id: DNS Extensions working group discussion list <dnsext.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dnsext>,
 <mailto:dnsext-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/dnsext/>
List-Post: <mailto:dnsext@ietf.org>
List-Help: <mailto:dnsext-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dnsext>,
 <mailto:dnsext-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 20 Nov 2013 06:59:53 -0000

This is a multi-part message in MIME format.

------=_001_NextPart011677867318_=----
Content-Type: text/plain;
	charset="gb2312"
Content-Transfer-Encoding: base64

DQpnb29kIHdyaXRpbmcgb2YgdGhpcyBkcmFmdC4NCg0KSSBhbSBpbnRlcmVzdGVkIHRoZSBmb2xs
b3dpbmcgdGV4dCBpbiBzZWN0aW9uIDM6DQoiICAgMi4gIFRoZSBETlMgcGFja2V0IGhlYWRlciBp
cyBub3Qgc2lnbmVkLiAgVGhpcyBtZWFucyB0aGF0IGEgInN0YXR1czoNCiAgICAgICBOWERPTUFJ
TiIgY2FuIG5vdCBiZSB0cnVzdGVkLiAgSW4gZmFjdCB0aGUgZW50aXJlIGhlYWRlciBtYXkgYmUN
CiAgICAgICBmb3JnZWQsIGluY2x1ZGluZyB0aGUgQUQgYml0IChBRCBzdGFuZHMgZm9yIEF1dGhl
bnRpYyBEYXRhLCBzZWUNCiAgICAgICBSRkMgMzY1NSBbUkZDMzY1NV0pLCB3aGljaCBtYXkgZ2l2
ZSBzb21lIGZvb2QgZm9yIHRob3VnaHQ7DQoiDQpzbyBpZiB0aGUgcmVzb2x2ZXIgaXMgYXR0YWNr
ZWQsIHN1Y2ggYXMgaGFja2luZyB0aGUgInN0YXR1cyIgZmllbGQgb3IgdGhlIHdob2xlIGhlYWRl
ciwgd2hhdCB3aWxsIGhhcHBlbj8NCg0KDQoNCg0KDQpKaWFua2FuZyBZYW8NCg0KRnJvbTogVGVk
IExlbW9uDQpEYXRlOiAyMDEzLTExLTIwIDExOjMwDQpUbzogR3JvdXAgDQpTdWJqZWN0OiBbZG5z
ZXh0XSBBdXRoZW50aWNhdGVkIGRlbmlhbCBvZiBleGlzdGVuY2UuLi4NCklzIHRoaXMgb24gYW55
b25lJ3MgcmFkYXI/ICAgV2hhdCBhcmUgeW91ciB0aG91Z2h0cyBhYm91dCBpdD8NCg0KaHR0cHM6
Ly9kYXRhdHJhY2tlci5pZXRmLm9yZy9kb2MvZHJhZnQtZ2llYmVuLWF1dGgtZGVuaWFsLW9mLWV4
aXN0ZW5jZS1kbnMvDQoNCl9fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19f
X19fX19fDQpkbnNleHQgbWFpbGluZyBsaXN0DQpkbnNleHRAaWV0Zi5vcmcNCmh0dHBzOi8vd3d3
LmlldGYub3JnL21haWxtYW4vbGlzdGluZm8vZG5zZXh0

------=_001_NextPart011677867318_=----
Content-Type: text/html;
	charset="gb2312"
Content-Transfer-Encoding: quoted-printable

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<HTML><HEAD>
<META content=3D"text/html; charset=3Dgb2312" http-equiv=3DContent-Type>
<STYLE>
BLOCKQUOTE {
	MARGIN-TOP: 0px; MARGIN-BOTTOM: 0px; MARGIN-LEFT: 2em
}
OL {
	MARGIN-TOP: 0px; MARGIN-BOTTOM: 0px
}
UL {
	MARGIN-TOP: 0px; MARGIN-BOTTOM: 0px
}
BODY {
	LINE-HEIGHT: 1.5; FONT-FAMILY: verdana; COLOR: #000000; FONT-SIZE: 10pt
}
P {
	MARGIN-TOP: 0px; MARGIN-BOTTOM: 0px
}
</STYLE>

<META name=3DGENERATOR content=3D"MSHTML 8.00.7601.18283"></HEAD>
<BODY style=3D"MARGIN: 10px">
<DIV style=3D"FONT-FAMILY: Verdana">&nbsp;</DIV>
<DIV style=3D"FONT-FAMILY: Verdana">good writing of this draft.</DIV>
<DIV style=3D"FONT-FAMILY: Verdana">&nbsp;</DIV>
<DIV style=3D"FONT-FAMILY: Verdana">I am interested the following text in =
section=20
3:</DIV>
<DIV style=3D"FONT-FAMILY: Verdana">"&nbsp;&nbsp; 2.&nbsp; The DNS packet =
header=20
is not signed.&nbsp; This means that a=20
"status:<BR>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; NXDOMAIN" can not be=20
trusted.&nbsp; In fact the entire header may=20
be<BR>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; forged, including the AD bit (A=
D=20
stands for Authentic Data, see<BR>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; RFC=
 3655=20
[RFC3655]), which may give some food for thought;<BR>"</DIV>
<DIV style=3D"FONT-FAMILY: Verdana">so if the resolver is attacked, such a=
s=20
hacking the "status" field or the whole header, what will happen?</DIV>
<DIV style=3D"FONT-FAMILY: Verdana">&nbsp;</DIV>
<DIV>&nbsp;</DIV>
<HR style=3D"WIDTH: 210px; HEIGHT: 1px" align=3Dleft color=3D#b5c4df SIZE=
=3D1>

<DIV style=3D"FONT-FAMILY: Verdana"><SPAN>Jiankang Yao</SPAN></DIV>
<DIV>&nbsp;</DIV>
<DIV=20
style=3D"BORDER-BOTTOM: medium none; BORDER-LEFT: medium none; PADDING-BOT=
TOM: 0cm; PADDING-LEFT: 0cm; PADDING-RIGHT: 0cm; BORDER-TOP: #b5c4df 1pt s=
olid; BORDER-RIGHT: medium none; PADDING-TOP: 3pt">
<DIV=20
style=3D"PADDING-BOTTOM: 8px; PADDING-LEFT: 8px; PADDING-RIGHT: 8px; BACKG=
ROUND: #efefef; COLOR: #000000; FONT-SIZE: 12px; PADDING-TOP: 8px">
<DIV><B>From:</B>&nbsp;<A href=3D"mailto:ted.lemon@nominum.com">Ted=20
Lemon</A></DIV>
<DIV><B>Date:</B>&nbsp;2013-11-20&nbsp;11:30</DIV>
<DIV><B>To:</B>&nbsp;<A href=3D"mailto:dnsext@ietf.org">Group=20
<DNSEXT@IETF.ORG></A></DIV>
<DIV><B>Subject:</B>&nbsp;[dnsext] Authenticated denial of=20
existence...</DIV></DIV></DIV>
<DIV>
<DIV>Is&nbsp;this&nbsp;on&nbsp;anyone's&nbsp;radar?&nbsp;&nbsp;&nbsp;What&=
nbsp;are&nbsp;your&nbsp;thoughts&nbsp;about&nbsp;it?</DIV>
<DIV>&nbsp;</DIV>
<DIV>https://datatracker.ietf.org/doc/draft-gieben-auth-denial-of-existenc=
e-dns/</DIV>
<DIV>&nbsp;</DIV>
<DIV>_______________________________________________</DIV>
<DIV>dnsext&nbsp;mailing&nbsp;list</DIV>
<DIV>dnsext@ietf.org</DIV>
<DIV>https://www.ietf.org/mailman/listinfo/dnsext</DIV></DIV></BODY></HTML=
>

------=_001_NextPart011677867318_=------

