Re: [DNSOP] [dnsext] We want to have fruitful discussions - please review

神明達哉 <jinmei@wide.ad.jp> Mon, 03 March 2014 08:44 UTC

Return-Path: <jinmei.tatuya@gmail.com>
X-Original-To: dnsop@ietfa.amsl.com
Delivered-To: dnsop@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 433CF1A07B0; Mon, 3 Mar 2014 00:44:19 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: 1.922
X-Spam-Level: *
X-Spam-Status: No, score=1.922 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, CHARSET_FARAWAY_HEADER=3.2, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, FM_FORGED_GMAIL=0.622, FREEMAIL_FROM=0.001, SPF_PASS=-0.001] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id s6Gv69eet5Wn; Mon, 3 Mar 2014 00:44:18 -0800 (PST)
Received: from mail-we0-x234.google.com (mail-we0-x234.google.com [IPv6:2a00:1450:400c:c03::234]) by ietfa.amsl.com (Postfix) with ESMTP id D70BE1A0349; Mon, 3 Mar 2014 00:44:17 -0800 (PST)
Received: by mail-we0-f180.google.com with SMTP id p61so1615219wes.39 for <multiple recipients>; Mon, 03 Mar 2014 00:44:14 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=mime-version:sender:in-reply-to:references:date:message-id:subject :from:to:cc:content-type; bh=vTh3CaUsbb0W7dRAvzSQ/G8MrxxBnRtIlcLgV0bDEgU=; b=jv+7e9XVL4fiv2ni3ZVgn/hPu/RVx9TPDlwLOsDM3mHTxI1SAxWbVY2scWEOZdVMVM MzADc1VY4mlPt5Q+7f+7gFjWKqIXr9vjMacAohNc14V9jQKkghIIk+v8AKOojDXBHJ1M H7aGof96Mj4ro6c+5Gmmmqwne/iqE4BtNowNW7CuUgQJAlUr7JfD5sQWk42ElmwMUSZ+ Pw7oJMwa/fGyv27Zs0asXOKMQg44T9CGtSNIocnNQ+IZOgc7AOfk4SMumXUIQfKnC5Gg +HRCIXe3a/Ux7CyMSEGGIM2hTdLzsEZ0XngdIc3Bh7eVvk59Bo+UjZrT0eix5PxD/EzC Z+Kg==
MIME-Version: 1.0
X-Received: by 10.194.21.193 with SMTP id x1mr14998447wje.33.1393836254653; Mon, 03 Mar 2014 00:44:14 -0800 (PST)
Sender: jinmei.tatuya@gmail.com
Received: by 10.194.120.167 with HTTP; Mon, 3 Mar 2014 00:44:14 -0800 (PST)
In-Reply-To: <002101cf3495$1ad2d570$50788050$@rozanak.com>
References: <002101cf3495$1ad2d570$50788050$@rozanak.com>
Date: Mon, 03 Mar 2014 08:44:14 +0000
X-Google-Sender-Auth: rX7TXwaDzh3J-MIR8RhJl1XmLvI
Message-ID: <CAJE_bqdFknJ7Dy9QUJaQUj9Ca40TM0jWCfGNNyUSEkF5d39Rqw@mail.gmail.com>
From: 神明達哉 <jinmei@wide.ad.jp>
To: Hosnieh Rafiee <ietf@rozanak.com>
Content-Type: text/plain; charset="ISO-8859-1"
Archived-At: http://mailarchive.ietf.org/arch/msg/dnsop/ceTDpaIGzAf1nf5hd2TcWHjMp7U
Cc: dnsop <DNSOP@ietf.org>, DNSEXT Group Working <dnsext@ietf.org>
Subject: Re: [DNSOP] [dnsext] We want to have fruitful discussions - please review
X-BeenThere: dnsop@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dnsop>, <mailto:dnsop-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/dnsop/>
List-Post: <mailto:dnsop@ietf.org>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dnsop>, <mailto:dnsop-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 03 Mar 2014 08:44:19 -0000

I have one quick question for my own understanding:

At Fri, 28 Feb 2014 15:55:21 +0100,
"Hosnieh Rafiee" <ietf@rozanak.com> wrote:

> [...] For DNS resolver, it
> receives this IP address securely via the option in the router advertisement
> message.

So, the security of this approach relies on how securely the client
can get the resolver's address, e.g.,
- Using SEND for RAs with RFC 6106
- (If and when it's defined) Using public-key based DHCPv6
  authentication
And, to make this part secure, the client needs to get the router's
certification or the server's public key securely beforehand.

Is my understanding correct?

--
JINMEI, Tatuya