Re: [dnsext] we need help to make names the same, was draft-yao-dnsext-identical-resolution-02 comment

Phillip Hallam-Baker <hallam@gmail.com> Wed, 23 February 2011 03:47 UTC

Return-Path: <hallam@gmail.com>
X-Original-To: dnsext@core3.amsl.com
Delivered-To: dnsext@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id 0EC923A699E for <dnsext@core3.amsl.com>; Tue, 22 Feb 2011 19:47:48 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -3.56
X-Spam-Level:
X-Spam-Status: No, score=-3.56 tagged_above=-999 required=5 tests=[AWL=0.038, BAYES_00=-2.599, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_LOW=-1]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id kIhKUoy3juYD for <dnsext@core3.amsl.com>; Tue, 22 Feb 2011 19:47:46 -0800 (PST)
Received: from mail-bw0-f54.google.com (mail-bw0-f54.google.com [209.85.214.54]) by core3.amsl.com (Postfix) with ESMTP id 2450D3A6803 for <dnsext@ietf.org>; Tue, 22 Feb 2011 19:47:45 -0800 (PST)
Received: by bwz12 with SMTP id 12so4428958bwz.27 for <dnsext@ietf.org>; Tue, 22 Feb 2011 19:48:31 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=gamma; h=domainkey-signature:mime-version:in-reply-to:references:date :message-id:subject:from:to:cc:content-type; bh=Ag6dYPpApzGiRT574Nx3SoP1yIzGOK+EV+vCS92tc20=; b=Of8XzFYqS5z3lIwLC3kk1CLW5MFwePplNRr0uxzqHI2ZPezlqoPSjUg9KOxSh++QGS FgtpjJUFbNdE7e7US4ukC9DUgJ9CpeBZ+qANrOtQHjs783p08tn3+PysabwUkt4Jdk/u MrP3LN7D12rHZmxFrSOYZGm7HdnLOG/HkQDVM=
DomainKey-Signature: a=rsa-sha1; c=nofws; d=gmail.com; s=gamma; h=mime-version:in-reply-to:references:date:message-id:subject:from:to :cc:content-type; b=jzr9FY/TRmmZKcDLQU13qPORhsvFSqxC0TKsKFcTnpBotDQahHBmmWO+Z6hkJLkdFa 3A8lOA5DGuyivX+pmDtWVQH55x9PXKiHIDCHEPscTACmnBrujniyN50DxlNUxHw5mO4/ iBh6LTMptXt6msUJCmnuW8RsnFv0KRe+rGNQA=
MIME-Version: 1.0
Received: by 10.204.24.135 with SMTP id v7mr2792338bkb.99.1298432909799; Tue, 22 Feb 2011 19:48:29 -0800 (PST)
Received: by 10.204.14.139 with HTTP; Tue, 22 Feb 2011 19:48:29 -0800 (PST)
In-Reply-To: <713D992A-1DB9-4F72-9D18-8E923AD51D8D@icsi.berkeley.edu>
References: <20110216165921.GW96213@shinkuro.com> <3B90ED2E-980D-4B01-889F-447D66D0B58D@insensate.co.uk> <20110216174011.GZ96213@shinkuro.com> <20110218143653.GC84482@bikeshed.isc.org> <20110218151209.GF66684@shinkuro.com> <4D5EEE09.4080405@dougbarton.us> <20110218222950.GL74065@shinkuro.com> <4D5F270F.20401@abenaki.wabanaki.net> <199C7B2B4228461FB024E59A990DB46D@ics.forth.gr> <4D641DB6.4090705@necom830.hpcl.titech.ac.jp> <20110222205617.GS53815@shinkuro.com> <4D64489B.7020901@necom830.hpcl.titech.ac.jp> <713D992A-1DB9-4F72-9D18-8E923AD51D8D@icsi.berkeley.edu>
Date: Tue, 22 Feb 2011 22:48:29 -0500
Message-ID: <AANLkTikf2ixw7JkxQiRBobv-seYnaYS0E3G8TboosnA=@mail.gmail.com>
From: Phillip Hallam-Baker <hallam@gmail.com>
To: Nicholas Weaver <nweaver@icsi.berkeley.edu>
Content-Type: multipart/alternative; boundary="00032555ae825a72e2049ceaf89a"
Cc: dnsext@ietf.org
Subject: Re: [dnsext] we need help to make names the same, was draft-yao-dnsext-identical-resolution-02 comment
X-BeenThere: dnsext@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: DNS Extensions working group discussion list <dnsext.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/dnsext>, <mailto:dnsext-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/dnsext>
List-Post: <mailto:dnsext@ietf.org>
List-Help: <mailto:dnsext-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dnsext>, <mailto:dnsext-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 23 Feb 2011 03:47:48 -0000

If you are going to do that, you might as well do a key exchange inline as
well as we do in TLS.

One key exchange can then be leveraged across multiple connections using
kerberos style tickets (see DPLS for an example).


DNS does not require non-repudiation so this would be the appropriate
technology.




On Tue, Feb 22, 2011 at 9:02 PM, Nicholas Weaver
<nweaver@icsi.berkeley.edu>wrote:

>
> On Feb 22, 2011, at 3:36 PM, Masataka Ohta wrote:
> >
> > Specific proposals on the sameness problem I made this time are:
> >
> >       to give up to have localized domain name
> >
> > or
> >
> >       develop extended case insensitivity description language
> >
> > and
> >
> >       to give up DNSSEC or run extended case insensitivity
> >       database on clients
>
> OR use DNSSEC but sign data dynamically.
>
> 10 years ago, online signatures may have been questionable computationally.
>  Today, online signatures are near-trivial computationally.
>
> _______________________________________________
> dnsext mailing list
> dnsext@ietf.org
> https://www.ietf.org/mailman/listinfo/dnsext
>



-- 
Website: http://hallambaker.com/