[Hipsec-rg] reverse DNS lookups of HITs

oleg.ponomarev at hiit.fi (Oleg Ponomarev) Mon, 12 January 2009 20:38 UTC

From: "oleg.ponomarev at hiit.fi"
Date: Mon, 12 Jan 2009 22:38:32 +0200
Subject: [Hipsec-rg] reverse DNS lookups of HITs
In-Reply-To: <77F357662F8BFA4CA7074B0410171B6D07B0BC76@XCH-NW-5V1.nw.nos.boeing.com>
References: <77F357662F8BFA4CA7074B0410171B6D07B0BBE5@XCH-NW-5V1.nw.nos.boeing.com> <alpine.LFD.2.00.0901071641330.12787@stargazer.pc.infrahip.net> <77F357662F8BFA4CA7074B0410171B6D07B0BC6B@XCH-NW-5V1.nw.nos.boeing.com> <alpine.LFD.2.00.0901121802320.17180@stargazer.pc.infrahip.net><77F357662F8BFA4CA7074B0410171B6D07B0BC70@XCH-NW-5V1.nw.nos.boeing.com> <alpine.LFD.2.00.0901122112420.17180@stargazer.pc.infrahip.net> <77F357662F8BFA4CA7074B0410171B6D07B0BC76@XCH-NW-5V1.nw.nos.boeing.com>
Message-ID: <alpine.LFD.2.00.0901122213140.17180@stargazer.pc.infrahip.net>

Hi! On Mon, 12 Jan 2009, Henderson, Thomas R wrote:

> Yes, but how do you delegate below that top level?
>
> If I am a HIP user, and I generate a key for myself, how do I register
> it with A.OUR-SERVERS.NET.?  Do they have an open policy and let just
> anyone in the Internet add a record for themselves?

I would say yes. If there is a DoS attack, give puzzles.

> I see how one could technically build such a name server, but I'm
> wondering about the scalability of it and how it would operationally be
> deployed.

I guess one modern server could keep like ten million records in RAM? How 
many base exchanges can it do per second? Reverse DNS updates are rare 
anyway.

When HIP gets widely deployed and there are millions of users, we might 
hope to use more resources :)

-- 
Regards, Oleg.