Re: [dnsext] Historical root keys: The Large Router Vendor Speaks

Thierry Moreau <thierry.moreau@connotech.com> Fri, 28 January 2011 21:54 UTC

Return-Path: <thierry.moreau@connotech.com>
X-Original-To: dnsext@core3.amsl.com
Delivered-To: dnsext@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id ACA753A6975 for <dnsext@core3.amsl.com>; Fri, 28 Jan 2011 13:54:53 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: 0.527
X-Spam-Level:
X-Spam-Status: No, score=0.527 tagged_above=-999 required=5 tests=[AWL=0.964, BAYES_00=-2.599, FH_RELAY_NODNS=1.451, HELO_MISMATCH_ORG=0.611, RDNS_NONE=0.1]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id mIfXo6M4gds6 for <dnsext@core3.amsl.com>; Fri, 28 Jan 2011 13:54:53 -0800 (PST)
Received: from bretelle.intaglionic.org (unknown [76.10.176.241]) by core3.amsl.com (Postfix) with ESMTP id E12473A68C8 for <dnsext@ietf.org>; Fri, 28 Jan 2011 13:54:52 -0800 (PST)
Received: from [192.168.1.200] (unknown [192.168.1.200]) by bretelle.intaglionic.org (Postfix) with ESMTPA id 1080D3076C; Fri, 28 Jan 2011 22:09:05 -0500 (EST)
Message-ID: <4D433B9D.7030209@connotech.com>
Date: Fri, 28 Jan 2011 16:56:45 -0500
From: Thierry Moreau <thierry.moreau@connotech.com>
User-Agent: Thunderbird 2.0.0.17 (X11/20090608)
MIME-Version: 1.0
To: John Bashinski <jbash@cisco.com>
References: <4D41D3E2.6060107@cisco.com> <3125F45F-7594-498F-AFA3-D2D738A228F5@hopcount.ca> <4D42F597.8090006@vpnc.org> <4D42FCB6.70005@cisco.com> <4D43072D.6090503@vpnc.org> <4D431F94.4020701@cisco.com>
In-Reply-To: <4D431F94.4020701@cisco.com>
Content-Type: text/plain; charset="ISO-8859-1"; format="flowed"
Content-Transfer-Encoding: 7bit
Cc: Paul Hoffman <paul.hoffman@vpnc.org>, dnsext@ietf.org
Subject: Re: [dnsext] Historical root keys: The Large Router Vendor Speaks
X-BeenThere: dnsext@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: DNS Extensions working group discussion list <dnsext.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/dnsext>, <mailto:dnsext-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/dnsext>
List-Post: <mailto:dnsext@ietf.org>
List-Help: <mailto:dnsext-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dnsext>, <mailto:dnsext-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 28 Jan 2011 21:54:53 -0000

John Bashinski wrote:
> 
> It's not even part of the process if you maintain
> your anchors manually (as everybody does now). And it doesn't become any
> more central when anything goes wrong. It doesn't make any change
> in, say, how the system responds to key compromise, nor have I asked
> for any change in the key rollover schedule. All I've asked for is
> a history of rollovers, or something equivalent.
> 

But once IANA (or whichever organization makes it "public") commits to 
"it" on a long term it becomes by definition more trustworthy than the 
root KSK. Then suddenly the trust foundation shifts from the root KSK to 
"it" and soon it becomes best practice to use it as the normal way to 
bootstrap DNSSEC resolution.

At one point you reach the end of the world (the Earth is flat with 
respect to system-wide crypto key management).

> If you want to have more assurance in your trust anchors, you can ALWAYS
> install them manually, or check their fingerprints manually, exactly as
> you would today. You can use whatever out of band methods you
> want. Nobody's suggested taking that away. In fact, I'm expecting to
> take heat for requiring some quite sophisticated trust anchor managment
> to be available in products where it'll almost never get used. The
> present draft requires:
> 
> 1. User able to choose root keys (defaulting to whatever's learned
>    from the system we're talking about now).
> 

Ah ah! Now "it" becomes the (default) new trust foundation. I knew it 
would come sooner than later.

Have a good week-end and best regards,

-- 
- Thierry Moreau