[DNSOP] ip6.arpa reverse delegation
Michael Richardson <mcr+ietf@sandelman.ca> Sun, 23 November 2014 21:14 UTC
Return-Path: <mcr@sandelman.ca>
X-Original-To: dnsop@ietfa.amsl.com
Delivered-To: dnsop@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 03E291A1AAB; Sun, 23 Nov 2014 13:14:14 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: 1.987
X-Spam-Level: *
X-Spam-Status: No, score=1.987 tagged_above=-999 required=5 tests=[BAYES_40=-0.001, MIME_NO_TEXT=1.999, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id GcAoT2ykUVjC; Sun, 23 Nov 2014 13:14:13 -0800 (PST)
Received: from tuna.sandelman.ca (tuna.sandelman.ca [209.87.249.19]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 3CE911A1AAA; Sun, 23 Nov 2014 13:14:13 -0800 (PST)
Received: from sandelman.ca (obiwan.sandelman.ca [209.87.249.21]) by tuna.sandelman.ca (Postfix) with ESMTP id B764320098; Sun, 23 Nov 2014 16:16:58 -0500 (EST)
Received: by sandelman.ca (Postfix, from userid 179) id 86CB3637F5; Sun, 23 Nov 2014 16:14:12 -0500 (EST)
Received: from sandelman.ca (localhost [127.0.0.1]) by sandelman.ca (Postfix) with ESMTP id 7665263745; Sun, 23 Nov 2014 16:14:12 -0500 (EST)
From: Michael Richardson <mcr+ietf@sandelman.ca>
To: homenet@ietf.org, dnsop@ietf.org
X-Attribution: mcr
X-Mailer: MH-E 8.2; nmh 1.3; GNU Emacs 23.4.1
X-Face: $\n1pF)h^`}$H>Hk{L"x@)JS7<%Az}5RyS@k9X%29-lHB$Ti.V>2bi.~ehC0; <'$9xN5Ub# z!G,p`nR&p7Fz@^UXIn156S8.~^@MJ*mMsD7=QFeq%AL4m<nPbLgmtKK-5dC@#:k
MIME-Version: 1.0
Content-Type: multipart/signed; boundary="=-=-="; micalg="pgp-sha1"; protocol="application/pgp-signature"
Date: Sun, 23 Nov 2014 16:14:12 -0500
Message-ID: <29673.1416777252@sandelman.ca>
Sender: mcr@sandelman.ca
Archived-At: http://mailarchive.ietf.org/arch/msg/dnsop/jC2bd7pXqepGCffD3QX3akQfimw
X-Mailman-Approved-At: Sun, 23 Nov 2014 13:33:23 -0800
Subject: [DNSOP] ip6.arpa reverse delegation
X-BeenThere: dnsop@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dnsop>, <mailto:dnsop-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/dnsop/>
List-Post: <mailto:dnsop@ietf.org>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dnsop>, <mailto:dnsop-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sun, 23 Nov 2014 21:14:14 -0000
I have read: Automated Delegation of IP6.ARPA reverse zones with Prefix Delegation draft-andrews-dnsop-pd-reverse-02 as a method to delegate reverse zones to CPE devices as the prefix is delegated. I find the method entirely sensible, and I think highly secure. I don't know if this belongs in dnsop or in homenet (or dhcpv6, since a new DHCPv6 option is requested, and this enhances DHCPv6-PD): I'll let the INT and Ops ADs sort that out. I suggest that one of these WGs should adopt it, and even suggest that this document should Updates: 6204/7084. If I had the required code point, I would implement it today in an IPv6 ACS I work on (ServPOET), and contribute code to Barrier Breaker OpenWRT (to dnsmasq) to do the client end. I want to say that this is very similar to the way that the "wavesec" mechanism that the FreeS/WAN project experimented with a decade ago (a few Minneapolis and Atlanta IETF networks back around IETF50). We used DHCP to carry a key, this was installed by TSIG update by the DHCP(v4) server, and was used to populate the reverse DNS. The result was an IPsec laptop/32<->gateway(0.0.0.0/0) tunnel, using IPsec for security across the wireless rather than the WEP that was common at the time. -- Michael Richardson <mcr+IETF@sandelman.ca>, Sandelman Software Works -= IPv6 IoT consulting =-
- [DNSOP] ip6.arpa reverse delegation Michael Richardson
- Re: [DNSOP] [homenet] ip6.arpa reverse delegation Markus Stenberg
- Re: [DNSOP] [homenet] ip6.arpa reverse delegation Michael Richardson
- Re: [DNSOP] [homenet] ip6.arpa reverse delegation Ted Lemon
- Re: [DNSOP] [homenet] ip6.arpa reverse delegation Tero Kivinen
- Re: [DNSOP] [homenet] ip6.arpa reverse delegation Juliusz Chroboczek
- Re: [DNSOP] [homenet] ip6.arpa reverse delegation Nicholas Weaver
- Re: [DNSOP] [homenet] ip6.arpa reverse delegation Ted Lemon