Re: OFFTOPIC: DNSSEC groupthink versus improving DNS

Duane <duane@e164.org> Fri, 08 August 2008 01:14 UTC

Return-Path: <owner-namedroppers@ops.ietf.org>
X-Original-To: ietfarch-dnsext-archive@core3.amsl.com
Delivered-To: ietfarch-dnsext-archive@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id 636273A6C70; Thu, 7 Aug 2008 18:14:45 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -0.495
X-Spam-Level:
X-Spam-Status: No, score=-0.495 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, FH_RELAY_NODNS=1.451, HELO_MISMATCH_COM=0.553, RDNS_NONE=0.1]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id OX6t+JERQKwL; Thu, 7 Aug 2008 18:14:44 -0700 (PDT)
Received: from psg.com (psg.com [IPv6:2001:418:1::62]) by core3.amsl.com (Postfix) with ESMTP id 678F93A6C65; Thu, 7 Aug 2008 18:14:44 -0700 (PDT)
Received: from majordom by psg.com with local (Exim 4.69 (FreeBSD)) (envelope-from <owner-namedroppers@ops.ietf.org>) id 1KRGUu-000ATd-TO for namedroppers-data@psg.com; Fri, 08 Aug 2008 01:10:28 +0000
Received: from [208.82.100.153] (helo=mail.aus-biz.com) by psg.com with esmtps (TLSv1:AES256-SHA:256) (Exim 4.69 (FreeBSD)) (envelope-from <duane@e164.org>) id 1KRGUq-000AT3-PS for namedroppers@ops.ietf.org; Fri, 08 Aug 2008 01:10:26 +0000
Received: from [192.168.100.244] (dsl-48-19.qld1.net.au [125.168.48.19]) (using SSLv3 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (Client did not present a certificate) by mail.aus-biz.com (Postfix) with ESMTPSA id 7A9DBFF272; Fri, 8 Aug 2008 11:10:25 +1000 (EST)
Message-ID: <489B9CFB.30002@e164.org>
Date: Fri, 08 Aug 2008 11:10:19 +1000
From: Duane <duane@e164.org>
User-Agent: Thunderbird 2.0.0.16 (X11/20080724)
MIME-Version: 1.0
To: Mark Andrews <Mark_Andrews@isc.org>
CC: bert hubert <bert.hubert@netherlabs.nl>, Namedroppers <namedroppers@ops.ietf.org>
Subject: Re: OFFTOPIC: DNSSEC groupthink versus improving DNS
References: <200808080052.m780qMd2002912@drugs.dv.isc.org>
In-Reply-To: <200808080052.m780qMd2002912@drugs.dv.isc.org>
X-Enigmail-Version: 0.95.0
Content-Type: text/plain; charset="ISO-8859-1"
Content-Transfer-Encoding: 7bit
Sender: owner-namedroppers@ops.ietf.org
Precedence: bulk
List-ID: <namedroppers.ops.ietf.org>

Mark Andrews wrote:
> 	and the alterative is arbitary data insertion.
> 
> 	You could have online keys and sign every response with a
> 	ttl + clock skew based window.  This requires that the
> 	private key is on all slaves.  The crypto hardware guys
> 	will love you :-)

I'm working on it, I'm fighting 2 issues at present, one to standardise
attributes on OpenPGP keys for server purposes, and once that's sorted
and all the hubbub about DNS has died down the 2nd issue is using
encryption to provide both confidentiality and effectively remove the
need for signing at all.

Thanks to feed back from people in this group I've improve the draft
considerably but yea, the idea now is to setup a AES session key that is
good for X hours using an initial RSA encrypted request from the client.

> 	Note this is a implementation / deployment trade off.  The
> 	protocol supports either senario.

It's 2008 and hardware is cheap it's silly to think of 1960's credit
card processing models are even valid 10 years ago let alone now.

> 	Which can be completely automated.  Has already been in
> 	some senarios.  I havn't re-signed my zones for months
> 	despite using a 30 day expiry period on the signatures.

Shows how much DNSSEC is used by you then, otherwise you would be
rejecting your own DNS replies.

> 	It is set and forget.  More and more of the process will
> 	become "set and forget" as the tools develop.

You miss the point, that presentation outlined what is now, not what
will be when someone can be bothered to.

> 	Well if you know that the data will be stable for a year
> 	you can sign once a year.

At the vest least natural disasters don't stick to time tables last time
I checked.

> 	The tools today can take a signed zone and re-sign it as
> 	well as incrementing the SOA serial in the process.  Re-signing
> 	then reloading can be run from cron on a weekly basis.

That's a nice 'hack'

> 	Note the tools will only get better so the costs will
> 	continue to go down.  They have gone down enormously from
> 	the original design costs.

Again, I can only comment on what is, not what will be.

-- 

Best regards,
 Duane

--
to unsubscribe send a message to namedroppers-request@ops.ietf.org with
the word 'unsubscribe' in a single line as the message text body.
archive: <http://ops.ietf.org/lists/namedroppers/>