Re: Name ownership and LLMNR (Re: Last Call: 'Linklocal Multicast Name Resolution...)

Harald Tveit Alvestrand <harald@alvestrand.no> Fri, 02 September 2005 14:05 UTC

Received: from localhost.localdomain ([127.0.0.1] helo=megatron.ietf.org) by megatron.ietf.org with esmtp (Exim 4.32) id 1EBCAP-0001Qi-PP; Fri, 02 Sep 2005 10:05:17 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org) by megatron.ietf.org with esmtp (Exim 4.32) id 1EBCAN-0001Qa-5r for ietf@megatron.ietf.org; Fri, 02 Sep 2005 10:05:15 -0400
Received: from ietf-mx.ietf.org (ietf-mx [132.151.6.1]) by ietf.org (8.9.1a/8.9.1a) with ESMTP id KAA07848 for <ietf@ietf.org>; Fri, 2 Sep 2005 10:05:13 -0400 (EDT)
Received: from eikenes.alvestrand.no ([158.38.152.233]) by ietf-mx.ietf.org with esmtp (Exim 4.43) id 1EBCCW-0004Gp-HA for ietf@ietf.org; Fri, 02 Sep 2005 10:07:29 -0400
Received: from localhost (eikenes.alvestrand.no [127.0.0.1]) by eikenes.alvestrand.no (Postfix) with ESMTP id EFABE3200A6; Fri, 2 Sep 2005 16:04:41 +0200 (CEST)
Received: from eikenes.alvestrand.no ([127.0.0.1]) by localhost (eikenes.alvestrand.no [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 00535-06; Fri, 2 Sep 2005 16:04:38 +0200 (CEST)
Received: from halvestr-w2k02.emea.cisco.com (eikenes.alvestrand.no [127.0.0.1]) by eikenes.alvestrand.no (Postfix) with ESMTP id AF0C132009F; Fri, 2 Sep 2005 16:04:38 +0200 (CEST)
Date: Fri, 02 Sep 2005 15:20:06 +0200
From: Harald Tveit Alvestrand <harald@alvestrand.no>
To: Tony Finch <dot@dotat.at>, "Steven M. Bellovin" <smb@cs.columbia.edu>
Message-ID: <3E90032BE1B593717BDE92ED@B50854F0A9192E8EC6CDA126>
In-Reply-To: <Pine.LNX.4.60.0509021240140.13347@hermes-1.csi.cam.ac.uk>
References: <20050902112401.6F24E3BFE86@berkshire.machshav.com> <Pine.LNX.4.60.0509021240140.13347@hermes-1.csi.cam.ac.uk>
X-Mailer: Mulberry/4.0.3 (Win32)
MIME-Version: 1.0
X-Virus-Scanned: by amavisd-new at alvestrand.no
X-Spam-Score: 0.0 (/)
X-Scan-Signature: 39bd8f8cbb76cae18b7e23f7cf6b2b9f
Cc: Iljitsch van Beijnum <iljitsch@muada.com>, IETF General Discussion Mailing List <ietf@ietf.org>
Subject: Re: Name ownership and LLMNR (Re: Last Call: 'Linklocal Multicast Name Resolution...)
X-BeenThere: ietf@ietf.org
X-Mailman-Version: 2.1.5
Precedence: list
List-Id: IETF-Discussion <ietf.ietf.org>
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/ietf>, <mailto:ietf-request@ietf.org?subject=unsubscribe>
List-Post: <mailto:ietf@ietf.org>
List-Help: <mailto:ietf-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/ietf>, <mailto:ietf-request@ietf.org?subject=subscribe>
Content-Type: multipart/mixed; boundary="===============1607149112=="
Sender: ietf-bounces@ietf.org
Errors-To: ietf-bounces@ietf.org


--On 2. september 2005 12:46 +0100 Tony Finch <dot@dotat.at> wrote:

>> If you have the zone key, you can do the verification offline.
>
> How can you be expected to have the zone key of some random name that just
> turned up on your network?

you can always ask the guy for the zone key (and its signature).
you have to get a certificate chain that ends up at a root key you trust, 
of course.

Reducing the problem to a previously unsolved problem.... but if you only 
care about whether or not it's locally unique, you don't CARE whether it's 
authentic or not, so you don't have to fetch anything....
_______________________________________________
Ietf mailing list
Ietf@ietf.org
https://www1.ietf.org/mailman/listinfo/ietf