Re: OFFTOPIC: DNSSEC groupthink versus improving DNS

Mark Andrews <Mark_Andrews@isc.org> Fri, 08 August 2008 02:06 UTC

Return-Path: <owner-namedroppers@ops.ietf.org>
X-Original-To: ietfarch-dnsext-archive@core3.amsl.com
Delivered-To: ietfarch-dnsext-archive@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id 82C363A6C64; Thu, 7 Aug 2008 19:06:53 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.599
X-Spam-Level:
X-Spam-Status: No, score=-2.599 tagged_above=-999 required=5 tests=[BAYES_00=-2.599]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id dxF8stUL9pbh; Thu, 7 Aug 2008 19:06:52 -0700 (PDT)
Received: from psg.com (psg.com [IPv6:2001:418:1::62]) by core3.amsl.com (Postfix) with ESMTP id 875183A6C7B; Thu, 7 Aug 2008 19:06:52 -0700 (PDT)
Received: from majordom by psg.com with local (Exim 4.69 (FreeBSD)) (envelope-from <owner-namedroppers@ops.ietf.org>) id 1KRHIb-000Exq-HJ for namedroppers-data@psg.com; Fri, 08 Aug 2008 02:01:49 +0000
Received: from [2001:470:1f00:820:214:22ff:fed9:fbdc] (helo=drugs.dv.isc.org) by psg.com with esmtps (TLSv1:AES256-SHA:256) (Exim 4.69 (FreeBSD)) (envelope-from <marka@isc.org>) id 1KRHIX-000ExQ-BP for namedroppers@ops.ietf.org; Fri, 08 Aug 2008 02:01:47 +0000
Received: from drugs.dv.isc.org (localhost [127.0.0.1]) by drugs.dv.isc.org (8.14.2/8.14.2) with ESMTP id m7821bHu004699; Fri, 8 Aug 2008 12:01:37 +1000 (EST) (envelope-from marka@drugs.dv.isc.org)
Message-Id: <200808080201.m7821bHu004699@drugs.dv.isc.org>
To: Duane <duane@e164.org>
Cc: bert hubert <bert.hubert@netherlabs.nl>, Namedroppers <namedroppers@ops.ietf.org>
From: Mark Andrews <Mark_Andrews@isc.org>
Subject: Re: OFFTOPIC: DNSSEC groupthink versus improving DNS
In-reply-to: Your message of "Fri, 08 Aug 2008 11:10:19 +1000." <489B9CFB.30002@e164.org>
Date: Fri, 08 Aug 2008 12:01:37 +1000
Sender: owner-namedroppers@ops.ietf.org
Precedence: bulk
List-ID: <namedroppers.ops.ietf.org>

> Mark Andrews wrote:
> > 	and the alterative is arbitary data insertion.
> > 
> > 	You could have online keys and sign every response with a
> > 	ttl + clock skew based window.  This requires that the
> > 	private key is on all slaves.  The crypto hardware guys
> > 	will love you :-)
> 
> I'm working on it, I'm fighting 2 issues at present, one to standardise
> attributes on OpenPGP keys for server purposes, and once that's sorted
> and all the hubbub about DNS has died down the 2nd issue is using
> encryption to provide both confidentiality and effectively remove the
> need for signing at all.
> 
> Thanks to feed back from people in this group I've improve the draft
> considerably but yea, the idea now is to setup a AES session key that is
> good for X hours using an initial RSA encrypted request from the client.
> 
> > 	Note this is a implementation / deployment trade off.  The
> > 	protocol supports either senario.
> 
> It's 2008 and hardware is cheap it's silly to think of 1960's credit
> card processing models are even valid 10 years ago let alone now.
> 
> > 	Which can be completely automated.  Has already been in
> > 	some senarios.  I havn't re-signed my zones for months
> > 	despite using a 30 day expiry period on the signatures.
> 
> Shows how much DNSSEC is used by you then, otherwise you would be
> rejecting your own DNS replies.

	I missed the "by hand" part.

	I havn't re-signed my zones, by hand, for months despite
	using a 30 day expiry period on the signatures. 

	Completely automated re-signing.
 
> > 	It is set and forget.  More and more of the process will
> > 	become "set and forget" as the tools develop.
> 
> You miss the point, that presentation outlined what is now, not what
> will be when someone can be bothered to.
> 
> > 	Well if you know that the data will be stable for a year
> > 	you can sign once a year.
> 
> At the vest least natural disasters don't stick to time tables last time
> I checked.
> 
> > 	The tools today can take a signed zone and re-sign it as
> > 	well as incrementing the SOA serial in the process.  Re-signing
> > 	then reloading can be run from cron on a weekly basis.
> 
> That's a nice 'hack'
> 
> > 	Note the tools will only get better so the costs will
> > 	continue to go down.  They have gone down enormously from
> > 	the original design costs.
> 
> Again, I can only comment on what is, not what will be.
> 
> -- 
> 
> Best regards,
>  Duane
-- 
Mark Andrews, ISC
1 Seymour St., Dundas Valley, NSW 2117, Australia
PHONE: +61 2 9871 4742                 INTERNET: Mark_Andrews@isc.org

--
to unsubscribe send a message to namedroppers-request@ops.ietf.org with
the word 'unsubscribe' in a single line as the message text body.
archive: <http://ops.ietf.org/lists/namedroppers/>