Re: [DNSOP] search for reference

Dick Franks <rwfranks@acm.org> Sat, 31 December 2016 15:43 UTC

Return-Path: <rwfranks@gmail.com>
X-Original-To: dnsop@ietfa.amsl.com
Delivered-To: dnsop@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id CBEDF129446 for <dnsop@ietfa.amsl.com>; Sat, 31 Dec 2016 07:43:08 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.597
X-Spam-Level:
X-Spam-Status: No, score=-2.597 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, FREEMAIL_FORGED_FROMDOMAIN=0.001, FREEMAIL_FROM=0.001, HEADER_FROM_DIFFERENT_DOMAINS=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_LOW=-0.7, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id zaur2eJuxUIU for <dnsop@ietfa.amsl.com>; Sat, 31 Dec 2016 07:43:07 -0800 (PST)
Received: from mail-oi0-x235.google.com (mail-oi0-x235.google.com [IPv6:2607:f8b0:4003:c06::235]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 1B865129430 for <dnsop@ietf.org>; Sat, 31 Dec 2016 07:43:07 -0800 (PST)
Received: by mail-oi0-x235.google.com with SMTP id v84so446933805oie.3 for <dnsop@ietf.org>; Sat, 31 Dec 2016 07:43:07 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=mime-version:sender:in-reply-to:references:from:date:message-id :subject:to:cc; bh=KHUeszAH7RtWZ3azlqc1/TBXwEns+ixtrCoQmHnb5vo=; b=GCxVRnl5oo7lw3opiVPi+556nvlDACSmCgazm1w9EVk07b7hu0jrCIxGzDfNjTfXY0 iGBYrewK00VDeDnujhrKnuYAWsWfySdJe8ARiLURiM14+BK6FtTWEtr2MC56dxZnImI7 6T90TIbHzJhv+nwOSwqjUAJmMcDk14eNXb0/xj6dp9U2a7rOnFM69nc4Rt5tXX5pqH6h RUwl76UCResfkEoWL38gqyd8dmaeDn6D2ByNa8dSyURKmBJEP64YLJrXMXMiV094e/vg w4yihudYtbLCdLLb06AeCwKOrD+dQjT1/CxZB+A/a7jFlDmw2TEl1/JpHZHxxwpue2Yr 5meQ==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:sender:in-reply-to:references:from :date:message-id:subject:to:cc; bh=KHUeszAH7RtWZ3azlqc1/TBXwEns+ixtrCoQmHnb5vo=; b=DHn25XAnArLqhycxNFghRRzECU7s6APiTWQFOgiMY5YYVLs8vYbo1x0gCL3RQhDiGm 37jONzxEf7PJmNcUZHAwasO7Anx4I1eRCEk6c6+K7T5roTGwLiaBVPoUbzDbNCzjg+F4 W1sE+ecRwV7Eu2LybxPvQ98l85itOrEKk+jMQ6anm9zKGlNvceQyhoRNUigc4UIG0eVz A5doL/BI3RWTCMDJSKsw+QaX29DTGaniEDT3z3MQAGQGtlCZtP1sE4fsWaKj11NxxrPY 7CqpUK1yjqDQgL7AgiEAhtVLXpTnN+y3K4CBEFFdRyioFrImJAx8BNMXr3p5O13B0HdH djAQ==
X-Gm-Message-State: AIkVDXKsZOP59F0kUrxkZnHQMpDLd0EGNykI8+obzvWDDfBkKoDTukDcqs+WE7+wTwzhlTunxsmMnFA+1fQWDA==
X-Received: by 10.157.44.188 with SMTP id p57mr23059204otb.255.1483198986361; Sat, 31 Dec 2016 07:43:06 -0800 (PST)
MIME-Version: 1.0
Sender: rwfranks@gmail.com
Received: by 10.182.104.130 with HTTP; Sat, 31 Dec 2016 07:42:25 -0800 (PST)
In-Reply-To: <20161230122014.Horde.WGMiuu_SJB8EAleLGv_Gf1P@andreasschulze.de>
References: <20161230120013.Horde.od0o75vhrXZ6uxS_-ytkiLz@andreasschulze.de> <20161230111600.GA16576@jurassic> <20161230122014.Horde.WGMiuu_SJB8EAleLGv_Gf1P@andreasschulze.de>
From: Dick Franks <rwfranks@acm.org>
Date: Sat, 31 Dec 2016 15:42:25 +0000
X-Google-Sender-Auth: oD_lmvcWAYRttz2dpxeN5OlGDps
Message-ID: <CAKW6Ri67bKMgXWNJFqt7Xxg+X4CVF3TG8QFRfNJDQf7ttg=zTA@mail.gmail.com>
To: "A. Schulze" <sca@andreasschulze.de>
Content-Type: multipart/alternative; boundary="001a113b0a9eb69f390544f62c83"
Archived-At: <https://mailarchive.ietf.org/arch/msg/dnsop/iy3xxB4gGg0Lk6BWFqf4DWSzf6U>
Cc: IETF DNSOP WG <dnsop@ietf.org>
Subject: Re: [DNSOP] search for reference
X-BeenThere: dnsop@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dnsop>, <mailto:dnsop-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dnsop/>
List-Post: <mailto:dnsop@ietf.org>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dnsop>, <mailto:dnsop-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sat, 31 Dec 2016 15:43:09 -0000

If you generate keys using the dnssec-keygen that comes with BIND, then
ISC's arbitrary numbers are exposed as follows:

        HMAC-MD5        157        a.k.a.  HMAC-MD5.SIG-ALG.REG.INT
        HMAC-SHA1       161
        HMAC-SHA224   162
        HMAC-SHA256   163
        HMAC-SHA384   164
        HMAC-SHA512   165


Dick Franks
________________________


On 30 December 2016 at 11:20, A. Schulze <sca@andreasschulze.de> wrote:

>
> Mukund Sivaraman:
>
> TSIG uses DNS names for encoding the algorithm type.
>>
> I didn't expected that...
>
>
> Thanks!
>
>
>
> _______________________________________________
> DNSOP mailing list
> DNSOP@ietf.org
> https://www.ietf.org/mailman/listinfo/dnsop
>