Re: [DNSOP] [dnsext] Why ZSK rollover is a Bad Idea (tm)
Joe Abley <jabley@hopcount.ca> Wed, 07 October 2009 15:46 UTC
Return-Path: <jabley@hopcount.ca>
X-Original-To: dnsop@core3.amsl.com
Delivered-To: dnsop@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id 9B6ED28C105 for <dnsop@core3.amsl.com>; Wed, 7 Oct 2009 08:46:10 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.599
X-Spam-Level:
X-Spam-Status: No, score=-2.599 tagged_above=-999 required=5 tests=[BAYES_00=-2.599]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id gBDIMlWwoJXs for <dnsop@core3.amsl.com>; Wed, 7 Oct 2009 08:46:09 -0700 (PDT)
Received: from monster.hopcount.ca (monster.hopcount.ca [216.235.14.38]) by core3.amsl.com (Postfix) with ESMTP id D1BF93A657C for <dnsop@ietf.org>; Wed, 7 Oct 2009 08:46:03 -0700 (PDT)
Received: from [193.0.27.97] (helo=dhcp-27-97.ripemtg.ripe.net) by monster.hopcount.ca with esmtpsa (TLSv1:AES128-SHA:128) (Exim 4.69 (FreeBSD)) (envelope-from <jabley@hopcount.ca>) id 1MvYjr-000IIE-W9; Wed, 07 Oct 2009 15:47:40 +0000
Mime-Version: 1.0 (Apple Message framework v1076)
Content-Type: text/plain; charset="us-ascii"; format="flowed"; delsp="yes"
From: Joe Abley <jabley@hopcount.ca>
In-Reply-To: <p06240835c6f262857f02@[10.20.30.158]>
Date: Wed, 07 Oct 2009 16:47:39 +0100
Content-Transfer-Encoding: 7bit
Message-Id: <A501A997-9DA6-4594-8B75-180CF88BBEBD@hopcount.ca>
References: <1C586E51-D77C-406C-9B89-47276A9B41B2@ICSI.Berkeley.EDU> <p06240812c6f160ac1fb2@10.20.30.158> <d3aa5d00910061408y191bf863p48a6ec703553b67e@mail.gmail.com> <FB20C78E-3A72-409C-8406-2B8A00923783@NLnetLabs.nl> <712BBDEE-25FF-4E2E-A9E5-49E49162D41D@hopcount.ca> <p06240835c6f262857f02@[10.20.30.158]>
To: Paul Hoffman <paul.hoffman@vpnc.org>
X-Mailer: Apple Mail (2.1076)
Cc: Eric Rescorla <ekr@rtfm.com>, dnsop WG <dnsop@ietf.org>
Subject: Re: [DNSOP] [dnsext] Why ZSK rollover is a Bad Idea (tm)
X-BeenThere: dnsop@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/dnsop>, <mailto:dnsop-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/dnsop>
List-Post: <mailto:dnsop@ietf.org>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dnsop>, <mailto:dnsop-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 07 Oct 2009 15:46:10 -0000
On 2009-10-07, at 16:25, Paul Hoffman wrote: > At 2:22 PM +0100 10/7/09, Joe Abley wrote: >> From this perspective we might roll a ZSK more frequently than a >> KSK because the ZSK needs to be stored on-line to facilitate re- >> signing when the zone changes. With the KSK we have the option of >> keeping it off-line, and arguably the risk of compromise is >> consequently lower. Regular testing of the machinery is still >> important, however. > > Please define "on-line" and "off-line". The ZSK is exercised every time the zone changes. For some zones this is every few seconds. For the root zone it's twice per day. The equipment that performs the signing operation might well need to make use of the ZSK in an automated fashion, without human operators being present. This scenario is what I meant by "on-line". The KSK is exercised every time a signature over the apex DNSKEY RRSet is required. This might be far more infrequent than the ZSK use described above. If so, it might be plausible to store the KSK on a device which has no network access and no power, in a secure facility, and to make the use of it a manual operation involving procedures, auditors, witnesses, etc. This is what I meant by "off-line". I appreciate that there are other perfectly valid operational approaches in which the KSK is also kept on-line. > In the deployments I have heard of, both types of keys are stored > with the same security procedures, but the ZSK might be stored in a > physically different location (or not). The operational aspects of > using the two keys are nearly identical. Joe
- Re: [DNSOP] [dnsext] Why ZSK rollover is a Bad Id… Olaf Kolkman
- Re: [DNSOP] [dnsext] Why ZSK rollover is a Bad Id… Olaf Kolkman
- Re: [DNSOP] Why ZSK rollover is a Bad Idea (tm) Chris Thompson
- Re: [DNSOP] [dnsext] Why ZSK rollover is a Bad Id… Joe Abley
- Re: [DNSOP] [dnsext] Why ZSK rollover is a Bad Id… Thierry Moreau
- Re: [DNSOP] [dnsext] Why ZSK rollover is a Bad Id… Roy Arends
- Re: [DNSOP] [dnsext] Why ZSK rollover is a Bad Id… Joe Abley
- Re: [DNSOP] [dnsext] Why ZSK rollover is a Bad Id… Paul Hoffman
- Re: [DNSOP] [dnsext] Why ZSK rollover is a Bad Id… Eric Rescorla
- Re: [DNSOP] [dnsext] Why ZSK rollover is a Bad Id… Joe Abley
- Re: [DNSOP] Why ZSK rollover is a Bad Idea (tm) Doug Barton
- Re: [DNSOP] [dnsext] Why ZSK rollover is a Bad Id… Olaf Kolkman
- Re: [DNSOP] Why ZSK rollover is a Bad Idea (tm) Todd Glassey