Re: [DNSOP] Practical issues deploying DNSSEC into the home.
mrex@sap.com (Martin Rex) Fri, 13 September 2013 23:07 UTC
Return-Path: <mrex@sap.com>
X-Original-To: ietf@ietfa.amsl.com
Delivered-To: ietf@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id AB81321F9D3B for <ietf@ietfa.amsl.com>; Fri, 13 Sep 2013 16:07:40 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -9.505
X-Spam-Level:
X-Spam-Status: No, score=-9.505 tagged_above=-999 required=5 tests=[AWL=-0.745, BAYES_05=-1.11, HELO_EQ_DE=0.35, RCVD_IN_DNSWL_HI=-8]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id LDD5TrcDPi-u for <ietf@ietfa.amsl.com>; Fri, 13 Sep 2013 16:07:28 -0700 (PDT)
Received: from smtpde02.sap-ag.de (smtpde02.sap-ag.de [155.56.68.140]) by ietfa.amsl.com (Postfix) with ESMTP id 2F5DD11E811B for <ietf@ietf.org>; Fri, 13 Sep 2013 16:07:27 -0700 (PDT)
Received: from mail05.wdf.sap.corp by smtpde02.sap-ag.de (26) with ESMTP id r8DN7Noc011364 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=OK); Sat, 14 Sep 2013 01:07:23 +0200 (MEST)
Subject: Re: [DNSOP] Practical issues deploying DNSSEC into the home.
In-Reply-To: <5231A5EA.2090007@necom830.hpcl.titech.ac.jp>
To: Masataka Ohta <mohta@necom830.hpcl.titech.ac.jp>
Date: Sat, 14 Sep 2013 01:07:23 +0200
X-Mailer: ELM [version 2.4ME+ PL125 (25)]
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Type: text/plain; charset="US-ASCII"
Message-Id: <20130913230723.17DC51A966@ld9781.wdf.sap.corp>
From: mrex@sap.com
X-SAP: out
Cc: ietf@ietf.org
X-BeenThere: ietf@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
Reply-To: mrex@sap.com
List-Id: IETF-Discussion <ietf.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ietf>, <mailto:ietf-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ietf>
List-Post: <mailto:ietf@ietf.org>
List-Help: <mailto:ietf-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ietf>, <mailto:ietf-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 13 Sep 2013 23:07:40 -0000
Masataka Ohta wrote: > > > It is still a hierarchical model of trust. So at the top, if you > > don't trust Verisign for the .COM domain and PIR for the .ORG domain > > (and for people who are worried about the NSA, both of these are US > > corporations), the whole system falls apart. > > Right. PKI is fundamentally broken, because its fundamental > assumption that trusted third parties could exist is a total > fallacy. I believe the problem is slightly different. There is no problem with the assumption that trusted third party _could_ exist. The reason where PKI breaks badly is whenever the third party that Bob selected as _his_ third party is not a third party that Alice has volutarily chosen herself to trust. Instead, PKI forces Alice to trust dozens of third parties, one or more per every Bob out there. -Martin
- Re: Practical issues deploying DNSSEC into the ho… Russ Housley
- Re: Practical issues deploying DNSSEC into the ho… Joe Abley
- Practical issues deploying DNSSEC into the home. Jim Gettys
- Re: Practical issues deploying DNSSEC into the ho… Paul Wouters
- Re: Practical issues deploying DNSSEC into the ho… Joe Abley
- Re: Practical issues deploying DNSSEC into the ho… Phillip Hallam-Baker
- Re: [DNSOP] Practical issues deploying DNSSEC int… Ted Lemon
- Re: Practical issues deploying DNSSEC into the ho… SM
- Re: Practical issues deploying DNSSEC into the ho… Michael Richardson
- Re: Practical issues deploying DNSSEC into the ho… Tony Finch
- Re: Practical issues deploying DNSSEC into the ho… Joe Abley
- Re: Practical issues deploying DNSSEC into the ho… Olafur Gudmundsson
- Re: Practical issues deploying DNSSEC into the ho… Brian E Carpenter
- Re: Practical issues deploying DNSSEC into the ho… David Morris
- Re: Practical issues deploying DNSSEC into the ho… Olafur Gudmundsson
- Re: [DNSOP] Practical issues deploying DNSSEC int… Olafur Gudmundsson
- Re: [DNSOP] Practical issues deploying DNSSEC int… Olafur Gudmundsson
- Re: [DNSOP] Practical issues deploying DNSSEC int… Evan Hunt
- Re: [DNSOP] Practical issues deploying DNSSEC int… Dickson, Brian
- Re: [DNSOP] Practical issues deploying DNSSEC int… Nicholas Weaver
- Re: [DNSOP] Practical issues deploying DNSSEC int… Paul Wouters
- Re: [DNSOP] Practical issues deploying DNSSEC int… Phillip Hallam-Baker
- Re: [DNSOP] Practical issues deploying DNSSEC int… Joe Abley
- Re: [DNSOP] Practical issues deploying DNSSEC int… Phillip Hallam-Baker
- Re: [DNSOP] Practical issues deploying DNSSEC int… Randy Presuhn
- Re: [DNSOP] Practical issues deploying DNSSEC int… Phillip Hallam-Baker
- Re: [DNSOP] Practical issues deploying DNSSEC int… Masataka Ohta
- Re: [DNSOP] Practical issues deploying DNSSEC int… Tony Finch
- Re: [DNSOP] Practical issues deploying DNSSEC int… Arturo Servin
- Re: [DNSOP] Practical issues deploying DNSSEC int… Masataka Ohta
- Re: [DNSOP] Practical issues deploying DNSSEC int… Theodore Ts'o
- Re: [DNSOP] Practical issues deploying DNSSEC int… Masataka Ohta
- Re: [DNSOP] Practical issues deploying DNSSEC int… Tony Finch
- Re: [DNSOP] Practical issues deploying DNSSEC int… Ted Lemon
- Re: [DNSOP] Practical issues deploying DNSSEC int… Theodore Ts'o
- Re: [DNSOP] Practical issues deploying DNSSEC int… Nicholas Weaver
- Re: [DNSOP] Practical issues deploying DNSSEC int… Nicholas Weaver
- Re: [DNSOP] Practical issues deploying DNSSEC int… Paul Wouters
- Re: [DNSOP] Practical issues deploying DNSSEC int… Paul Wouters
- Re: [DNSOP] Practical issues deploying DNSSEC int… Ted Lemon
- Re: [DNSOP] Practical issues deploying DNSSEC int… Paul Wouters
- Re: [DNSOP] Practical issues deploying DNSSEC int… Ted Lemon
- Re: [DNSOP] Practical issues deploying DNSSEC int… Theodore Ts'o
- Re: [DNSOP] Practical issues deploying DNSSEC int… Ted Lemon
- Re: [DNSOP] Practical issues deploying DNSSEC int… Ted Lemon
- Re: [DNSOP] Practical issues deploying DNSSEC int… Phillip Hallam-Baker
- Re: [DNSOP] Practical issues deploying DNSSEC int… Phillip Hallam-Baker
- Re: [DNSOP] Practical issues deploying DNSSEC int… Masataka Ohta
- Re: [DNSOP] Practical issues deploying DNSSEC int… Masataka Ohta
- Re: [DNSOP] Practical issues deploying DNSSEC int… David Morris
- Re: [DNSOP] Practical issues deploying DNSSEC int… Eliot Lear
- Re: [DNSOP] Practical issues deploying DNSSEC int… Dickson, Brian
- Re: [DNSOP] Practical issues deploying DNSSEC int… robert bownes
- Re: [DNSOP] Practical issues deploying DNSSEC int… Nicholas Weaver
- Re: [DNSOP] Practical issues deploying DNSSEC int… Glen Wiley
- Re: [DNSOP] Practical issues deploying DNSSEC int… Martin Rex
- Re: [DNSOP] Practical issues deploying DNSSEC int… Masataka Ohta
- Re: [DNSOP] Practical issues deploying DNSSEC int… Masataka Ohta
- Re: [DNSOP] Practical issues deploying DNSSEC int… Masataka Ohta
- Re: [DNSOP] Practical issues deploying DNSSEC int… Jim Gettys
- Re: [DNSOP] Practical issues deploying DNSSEC int… Masataka Ohta