Re: [DNSOP] New Version Notification for draft-wessels-dns-zone-digest-01.txt

Ondřej Surý <ondrej@isc.org> Mon, 30 July 2018 07:19 UTC

Return-Path: <ondrej@isc.org>
X-Original-To: dnsop@ietfa.amsl.com
Delivered-To: dnsop@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 91DF9130EB5 for <dnsop@ietfa.amsl.com>; Mon, 30 Jul 2018 00:19:21 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -6.9
X-Spam-Level:
X-Spam-Status: No, score=-6.9 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_HI=-5, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 9kUXq34ONR8i for <dnsop@ietfa.amsl.com>; Mon, 30 Jul 2018 00:19:20 -0700 (PDT)
Received: from mx.pao1.isc.org (mx.pao1.isc.org [IPv6:2001:4f8:0:2::2b]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 3A97E130E36 for <dnsop@ietf.org>; Mon, 30 Jul 2018 00:19:20 -0700 (PDT)
Received: from zmx1.isc.org (zmx1.isc.org [149.20.0.20]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by mx.pao1.isc.org (Postfix) with ESMTPS id B227A3AB004; Mon, 30 Jul 2018 07:19:18 +0000 (UTC)
Received: from zmx1.isc.org (localhost [127.0.0.1]) by zmx1.isc.org (Postfix) with ESMTPS id 9A63716006D; Mon, 30 Jul 2018 07:19:18 +0000 (UTC)
Received: from localhost (localhost [127.0.0.1]) by zmx1.isc.org (Postfix) with ESMTP id 823FE16006C; Mon, 30 Jul 2018 07:19:18 +0000 (UTC)
Received: from zmx1.isc.org ([127.0.0.1]) by localhost (zmx1.isc.org [127.0.0.1]) (amavisd-new, port 10026) with ESMTP id UhRyb5Ts2jLU; Mon, 30 Jul 2018 07:19:18 +0000 (UTC)
Received: from [100.101.176.193] (ip-37-188-149-70.eurotel.cz [37.188.149.70]) by zmx1.isc.org (Postfix) with ESMTPSA id 3135D160041; Mon, 30 Jul 2018 07:19:18 +0000 (UTC)
Content-Type: text/plain; charset="utf-8"
Mime-Version: 1.0 (1.0)
From: Ondřej Surý <ondrej@isc.org>
X-Mailer: iPhone Mail (16A5327f)
In-Reply-To: <20180729210344.GA39601@isc.org>
Date: Mon, 30 Jul 2018 09:19:14 +0200
Cc: John R Levine <johnl@taugh.com>, dnsop@ietf.org
Content-Transfer-Encoding: quoted-printable
Message-Id: <1437EC59-28F0-413E-97C4-9A886EDCA30E@isc.org>
References: <20180728215805.E60F020030A8E0@ary.qy> <FC43CF7A-9653-4EF3-BFF5-79600DC940AD@isc.org> <alpine.OSX.2.21.1807290047300.46393@ary.qy> <D2923107-B7D1-4ED6-AAC6-C65553BDEFEB@isc.org> <20180729210344.GA39601@isc.org>
To: Evan Hunt <each@isc.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/dnsop/e6HkIOyVoZNwnals-LRCm3LBvfQ>
Subject: Re: [DNSOP] New Version Notification for draft-wessels-dns-zone-digest-01.txt
X-BeenThere: dnsop@ietf.org
X-Mailman-Version: 2.1.27
Precedence: list
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dnsop>, <mailto:dnsop-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dnsop/>
List-Post: <mailto:dnsop@ietf.org>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dnsop>, <mailto:dnsop-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 30 Jul 2018 07:19:22 -0000

I know some people have 40Gbps at mothers house, but for general usefulness you want to prevent downloading fake (or otherwise invalid) zone before you start downloading it.

Especially, it might be very harmful if the client could be tricked into downloading any data distributed via torrent. You don’t want SWAT unit knocking down your door because your nameserver downloaded Universal Declaration of Human Rights.

Ondřej 
--
Ondřej Surý — ISC

> On 29 Jul 2018, at 23:03, Evan Hunt <each@isc.org> wrote:
> 
>> On Sun, Jul 29, 2018 at 10:55:31AM +0200, Ondřej Surý wrote:
>> You need to know the hash is valid before you start the download.
>> Therefore the hash has to be signed.
> 
> Before you *start* the download? Or before you use what you downloaded?
> 
> -- 
> Evan Hunt -- each@isc.org
> Internet Systems Consortium, Inc.