Re: Name ownership and LLMNR (Re: Last Call: 'Linklocal Multicast Name Resolution...)

Harald Tveit Alvestrand <harald@alvestrand.no> Thu, 01 September 2005 22:17 UTC

Received: from localhost.localdomain ([127.0.0.1] helo=megatron.ietf.org) by megatron.ietf.org with esmtp (Exim 4.32) id 1EAxNc-0001Hn-6j; Thu, 01 Sep 2005 18:17:56 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org) by megatron.ietf.org with esmtp (Exim 4.32) id 1EAxNZ-0001Hc-Nk for ietf@megatron.ietf.org; Thu, 01 Sep 2005 18:17:54 -0400
Received: from ietf-mx.ietf.org (ietf-mx [132.151.6.1]) by ietf.org (8.9.1a/8.9.1a) with ESMTP id SAA03019 for <ietf@ietf.org>; Thu, 1 Sep 2005 18:17:51 -0400 (EDT)
Received: from eikenes.alvestrand.no ([158.38.152.233]) by ietf-mx.ietf.org with esmtp (Exim 4.43) id 1EAxPa-0006sh-Mg for ietf@ietf.org; Thu, 01 Sep 2005 18:20:00 -0400
Received: from localhost (eikenes.alvestrand.no [127.0.0.1]) by eikenes.alvestrand.no (Postfix) with ESMTP id 30AD53200AB; Fri, 2 Sep 2005 00:17:24 +0200 (CEST)
Received: from eikenes.alvestrand.no ([127.0.0.1]) by localhost (eikenes.alvestrand.no [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 05101-10; Fri, 2 Sep 2005 00:17:20 +0200 (CEST)
Received: from [192.168.1.145] (163.80-203-220.nextgentel.com [80.203.220.163]) by eikenes.alvestrand.no (Postfix) with ESMTP id 1D9083200A6; Fri, 2 Sep 2005 00:17:19 +0200 (CEST)
Date: Fri, 02 Sep 2005 00:17:37 +0200
From: Harald Tveit Alvestrand <harald@alvestrand.no>
To: Iljitsch van Beijnum <iljitsch@muada.com>
Message-ID: <497781FA6773C9280C6121E3@gloppen.hjemme.alvestrand.no>
In-Reply-To: <E7D5D22F-B4FD-4B05-813E-347B90C2A896@muada.com>
References: <DAC3FCB50E31C54987CD10797DA511BA1096B57F@WIN-MSG-10.wingroup.win deploy.n tdev.microsoft.com> <p06230956bf3bd9a4992d@[17.202.35.52]> <431676B7.5040302@cs.utk.edu> <B2C6F40E0409805428ED7669@B50854F0A9192E8EC6CDA126> <Pine.LNX.4.60.0509011352580.13347@hermes-1.csi.cam.ac.uk> <8A8B241D9FAA21D02F463B3F@B50854F0A9192E8EC6CDA126> <E7D5D22F-B4FD-4B05-813E-347B90C2A896@muada.com>
X-Mailer: Mulberry/3.1.6 (Linux/x86)
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"; format="flowed"
Content-Transfer-Encoding: 7bit
Content-Disposition: inline
X-Virus-Scanned: by amavisd-new at alvestrand.no
X-Spam-Score: 0.0 (/)
X-Scan-Signature: b19722fc8d3865b147c75ae2495625f2
Content-Transfer-Encoding: 7bit
Cc: IETF General Discussion Mailing List <ietf@ietf.org>
Subject: Re: Name ownership and LLMNR (Re: Last Call: 'Linklocal Multicast Name Resolution...)
X-BeenThere: ietf@ietf.org
X-Mailman-Version: 2.1.5
Precedence: list
List-Id: IETF-Discussion <ietf.ietf.org>
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/ietf>, <mailto:ietf-request@ietf.org?subject=unsubscribe>
List-Post: <mailto:ietf@ietf.org>
List-Help: <mailto:ietf-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/ietf>, <mailto:ietf-request@ietf.org?subject=subscribe>
Sender: ietf-bounces@ietf.org
Errors-To: ietf-bounces@ietf.org


--On torsdag, september 01, 2005 20:30:56 +0200 Iljitsch van Beijnum 
<iljitsch@muada.com> wrote:

>> "You choose" in the DNS case is because you believe (presumably) in
>> the chain of servers between you, the root node and the
>> authoritative server for my domain; in the LLMNR *or* mDNS case, it
>> would be "because he's here and he says so".
>
> What I'm missing in this story is how the application finds out who  said
> so. So either you need to allow "Harald said so" for all  applications or
> for none of them. That is not good.

Yep.
In the DNS case, "the DNS server I asked said so".
In the LLMNR and mDNS case, "the machine that answered my multicast said 
so".

Flight of imagination: DNSSEC-Signed records (with the SIG/KEY chain in 
additional data?) would seem to be one possibility to "prove" that the data 
being presented was "legitimate" under DNS delegation rules, even when you 
don't have a present connection to the Internet.

My imagination doesn't fly far enough at this time of night to figure out 
any relationship beteen a ".local" name and the term "legitimacy". But it's 
late in the evening, so my imagination is not flying very far - perhaps 
mDNS works because they deliberately abandoned the idea of name ownership.

YMMV.

                       Harald


_______________________________________________
Ietf mailing list
Ietf@ietf.org
https://www1.ietf.org/mailman/listinfo/ietf