Re: [DNSOP] Whiskey Tango Foxtrot on key lengths...

Phillip Hallam-Baker <hallam@gmail.com> Thu, 27 March 2014 15:10 UTC

Return-Path: <hallam@gmail.com>
X-Original-To: dnsop@ietfa.amsl.com
Delivered-To: dnsop@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 5D2951A06E8 for <dnsop@ietfa.amsl.com>; Thu, 27 Mar 2014 08:10:42 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.999
X-Spam-Level:
X-Spam-Status: No, score=-1.999 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 53TIISuKYm4y for <dnsop@ietfa.amsl.com>; Thu, 27 Mar 2014 08:10:40 -0700 (PDT)
Received: from mail-la0-x22c.google.com (mail-la0-x22c.google.com [IPv6:2a00:1450:4010:c03::22c]) by ietfa.amsl.com (Postfix) with ESMTP id 9FF871A0159 for <dnsop@ietf.org>; Thu, 27 Mar 2014 08:10:39 -0700 (PDT)
Received: by mail-la0-f44.google.com with SMTP id hr13so2751191lab.31 for <dnsop@ietf.org>; Thu, 27 Mar 2014 08:10:37 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=mime-version:in-reply-to:references:date:message-id:subject:from:to :cc:content-type; bh=eSUMAgcNsHA6NXwObzhbQNkiAIldNUt2c1sCpVu+0X0=; b=m8cFDjS8PJDGAX9J8FAN/++ii7vLKmGV0xOsXn9J48t+FTio6Gf8rzoKU0NCDv9kJl AYGU0fDJL460jebEe2CRa2cciOIlhNzfniA5aEzpSdiwwPPCEkkhnpsQ3UBJbb2Ssnkt XjEIlisXBKJINyoHWnLJltioPxJ/vTQGDOgkdjJ2+uVG0u+YaQGC9FgrdpmSvvf7aY52 bZ2r0T4ds63aRQV95Ijz7Urbaw+hhbOFScY3SVTboqnqiPMh3I8B7fcvm99nc1UkljCV CGui8PWxeZqiesSM3yTGUmYygQUnld3hTCPN0U31GjXZZV1q4dLZ5/dn3Zrt3iW+tsIg 4eHg==
MIME-Version: 1.0
X-Received: by 10.112.163.69 with SMTP id yg5mr1271120lbb.14.1395933037191; Thu, 27 Mar 2014 08:10:37 -0700 (PDT)
Received: by 10.112.234.229 with HTTP; Thu, 27 Mar 2014 08:10:37 -0700 (PDT)
In-Reply-To: <FD66BB69-7F6E-4479-B99A-F84F9B7465A7@icsi.berkeley.edu>
References: <0EA28BE8-E872-46BA-85FD-7333A1E13172@icsi.berkeley.edu> <D9C84C71-1C87-48B3-AFAD-9F9D4AD97649@hopcount.ca> <FD66BB69-7F6E-4479-B99A-F84F9B7465A7@icsi.berkeley.edu>
Date: Thu, 27 Mar 2014 11:10:37 -0400
Message-ID: <CAMm+LwhgYocZmxCwhit_SF1xyEYgQSYYOEmhCH_YHpzFpB6rOA@mail.gmail.com>
From: Phillip Hallam-Baker <hallam@gmail.com>
To: Nicholas Weaver <nweaver@icsi.berkeley.edu>
Content-Type: multipart/alternative; boundary="089e0118294ecfea8104f597fc9c"
Archived-At: http://mailarchive.ietf.org/arch/msg/dnsop/jIFxh7YtKrs6RYIyV72fW0cyYjU
Cc: dnsop WG <dnsop@ietf.org>, Joe Abley <jabley@hopcount.ca>
Subject: Re: [DNSOP] Whiskey Tango Foxtrot on key lengths...
X-BeenThere: dnsop@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dnsop>, <mailto:dnsop-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/dnsop/>
List-Post: <mailto:dnsop@ietf.org>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dnsop>, <mailto:dnsop-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 27 Mar 2014 15:10:42 -0000

On Thu, Mar 27, 2014 at 11:05 AM, Nicholas Weaver <nweaver@icsi.berkeley.edu
> wrote:

>
> Frankly speaking, since the root uses NSEC rather than NSEC3, IMO it
> should be 4096b for both the KSK and ZSK.  But I'd be happy with 2048b.
>  Using 1024b is a recipe to ensure that DNSSEC is not taken seriously.
>
>
I think I know how to get this fixed.

I'll just tell the New York Times that DNSSEC has to be still considered a
science project until they stop relying on obsolete crypto.


-- 
Website: http://hallambaker.com/