Re: OFFTOPIC: DNSSEC groupthink versus improving DNS

Mark Andrews <Mark_Andrews@isc.org> Fri, 08 August 2008 01:01 UTC

Return-Path: <owner-namedroppers@ops.ietf.org>
X-Original-To: ietfarch-dnsext-archive@core3.amsl.com
Delivered-To: ietfarch-dnsext-archive@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id 6ED4D3A6C71; Thu, 7 Aug 2008 18:01:03 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.599
X-Spam-Level:
X-Spam-Status: No, score=-2.599 tagged_above=-999 required=5 tests=[BAYES_00=-2.599]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id bcjfCgajVtWP; Thu, 7 Aug 2008 18:01:02 -0700 (PDT)
Received: from psg.com (psg.com [IPv6:2001:418:1::62]) by core3.amsl.com (Postfix) with ESMTP id 27DD63A6C64; Thu, 7 Aug 2008 18:01:02 -0700 (PDT)
Received: from majordom by psg.com with local (Exim 4.69 (FreeBSD)) (envelope-from <owner-namedroppers@ops.ietf.org>) id 1KRGDh-0008pp-70 for namedroppers-data@psg.com; Fri, 08 Aug 2008 00:52:41 +0000
Received: from [2001:470:1f00:820:214:22ff:fed9:fbdc] (helo=drugs.dv.isc.org) by psg.com with esmtps (TLSv1:AES256-SHA:256) (Exim 4.69 (FreeBSD)) (envelope-from <marka@isc.org>) id 1KRGDb-0008oj-V4 for namedroppers@ops.ietf.org; Fri, 08 Aug 2008 00:52:39 +0000
Received: from drugs.dv.isc.org (localhost [127.0.0.1]) by drugs.dv.isc.org (8.14.2/8.14.2) with ESMTP id m780qMd2002912; Fri, 8 Aug 2008 10:52:22 +1000 (EST) (envelope-from marka@drugs.dv.isc.org)
Message-Id: <200808080052.m780qMd2002912@drugs.dv.isc.org>
To: Duane <duane@e164.org>
Cc: bert hubert <bert.hubert@netherlabs.nl>, Namedroppers <namedroppers@ops.ietf.org>
From: Mark Andrews <Mark_Andrews@isc.org>
Subject: Re: OFFTOPIC: DNSSEC groupthink versus improving DNS
In-reply-to: Your message of "Fri, 08 Aug 2008 00:43:10 +1000." <489B09FE.8050701@e164.org>
Date: Fri, 08 Aug 2008 10:52:22 +1000
Sender: owner-namedroppers@ops.ietf.org
Precedence: bulk
List-ID: <namedroppers.ops.ietf.org>

> bert hubert wrote:
> > Or 79 page presentations called "DNSSEC in six minutes" - giving people 4.6
> > seconds per page. It is just not real.
> > http://www.isc.org/sw/bind/docs/DNSSEC_in_6_minutes.pdf 
> 
> I've seen this document in the past and it actually turned me and others
> completely off the idea of DNSSEC, which in part was what led to me
> playing with encryption funnily enough, because it seems to me most are
> promoting 30 day TTLs on the sigs, which means 30 days of replay attacks
> potentially,

	and the alterative is arbitary data insertion.

	You could have online keys and sign every response with a
	ttl + clock skew based window.  This requires that the
	private key is on all slaves.  The crypto hardware guys
	will love you :-)

	Note this is a implementation / deployment trade off.  The
	protocol supports either senario.

> not to mention the whole re-signing every 30 days.

	Which can be completely automated.  Has already been in
	some senarios.  I havn't re-signed my zones for months
	despite using a 30 day expiry period on the signatures.

	It is set and forget.  More and more of the process will
	become "set and forget" as the tools develop.

> Who ever thought that does not live in the real world, people
> administering servers with X.509 certs that expire yearly is bad enough,
> but every 30 days or less???

	Well if you know that the data will be stable for a year
	you can sign once a year.
 
> That alone is going to be a show stopped for most if not all admins with
> too many things to do and not enough time to do everything.

	The tools today can take a signed zone and re-sign it as
	well as incrementing the SOA serial in the process.  Re-signing
	then reloading can be run from cron on a weekly basis.

	Note the tools will only get better so the costs will
	continue to go down.  They have gone down enormously from
	the original design costs.

	Mark
> -- 
> 
> Best regards,
>  Duane
-- 
Mark Andrews, ISC
1 Seymour St., Dundas Valley, NSW 2117, Australia
PHONE: +61 2 9871 4742                 INTERNET: Mark_Andrews@isc.org

--
to unsubscribe send a message to namedroppers-request@ops.ietf.org with
the word 'unsubscribe' in a single line as the message text body.
archive: <http://ops.ietf.org/lists/namedroppers/>