Re: [dnsext] we need help to make names the same, was draft-yao-dnsext-identical-resolution-02 comment

"John R. Levine" <johnl@iecc.com> Wed, 16 February 2011 17:43 UTC

Return-Path: <dnsext-bounces@ietf.org>
X-Original-To: namedroppers-archive-gleetwall6@lists.ietf.org
Delivered-To: ietfarch-namedroppers-archive-gleetwall6@core3.amsl.com
Received: from [127.0.0.1] (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id 8FCFA3A6ECB; Wed, 16 Feb 2011 09:43:53 -0800 (PST)
X-Original-To: dnsext@core3.amsl.com
Delivered-To: dnsext@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id 7B41C3A6ECB for <dnsext@core3.amsl.com>; Wed, 16 Feb 2011 09:43:52 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -111.199
X-Spam-Level:
X-Spam-Status: No, score=-111.199 tagged_above=-999 required=5 tests=[AWL=0.000, BAYES_00=-2.599, HABEAS_ACCREDITED_SOI=-4.3, RCVD_IN_BSP_TRUSTED=-4.3, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 0KorINAe180z for <dnsext@core3.amsl.com>; Wed, 16 Feb 2011 09:43:51 -0800 (PST)
Received: from gal.iecc.com (gal.iecc.com [64.57.183.53]) by core3.amsl.com (Postfix) with ESMTP id 071F23A6EC7 for <dnsext@ietf.org>; Wed, 16 Feb 2011 09:43:50 -0800 (PST)
Received: (qmail 548 invoked from network); 16 Feb 2011 17:44:18 -0000
DKIM-Signature: v=1; a=rsa-sha256; c=simple; d=iecc.com; h=date:message-id:from:to:cc:subject:in-reply-to:references:mime-version:content-type:vbr-info:user-agent:cleverness; s=223.4d5c0cf2.k1102; i=johnl@submit.iecc.com; bh=MdScmUt4Zu3l2htZZYvJsqQrRzkXLQqu/UR9I1WINS4=; b=GRFEwo1pm3klvS9cBHovyv6Jxfj8GdMYGlyCdX25zoyaZKBrVIbuJaunl9OTTybZJt7uKUm+NxoIbXi2L1uv2rJI7WMkKOtJO3Uqlz9N9XgMqQAL0lONWD21f1rYbSFD9OdwU/xu4TQWkkVDtpT1/SHNf9yAxPTDd4lDYWKfGO8=
VBR-Info: md=iecc.com; mc=all; mv=dwl.spamhaus.org
Received: (ofmipd johnl@64.57.183.62) with (DHE-RSA-AES256-SHA encrypted) SMTP; 16 Feb 2011 17:43:56 -0000
Date: Wed, 16 Feb 2011 09:44:16 -0800
Message-ID: <alpine.BSF.2.00.1102160942130.62118@joyce.lan>
From: "John R. Levine" <johnl@iecc.com>
To: Alex Bligh <alex@alex.org.uk>
In-Reply-To: <C304511C4F12CA122C84D7E0@nimrod.local>
References: <20110216073338.7251.qmail@joyce.lan> <BE5119E0A9AF9C470D3D362A@nimrod.local> <alpine.BSF.2.00.1102152352430.11303@joyce.lan> <C304511C4F12CA122C84D7E0@nimrod.local>
User-Agent: Alpine 2.00 (BSF 1167 2008-08-23)
Cleverness: None detected
MIME-Version: 1.0
Cc: dnsext@ietf.org
Subject: Re: [dnsext] we need help to make names the same, was draft-yao-dnsext-identical-resolution-02 comment
X-BeenThere: dnsext@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: DNS Extensions working group discussion list <dnsext.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/dnsext>, <mailto:dnsext-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/dnsext>
List-Post: <mailto:dnsext@ietf.org>
List-Help: <mailto:dnsext-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dnsext>, <mailto:dnsext-request@ietf.org?subject=subscribe>
Content-Transfer-Encoding: 7bit
Content-Type: text/plain; charset="us-ascii"; Format="flowed"
Sender: dnsext-bounces@ietf.org
Errors-To: dnsext-bounces@ietf.org

>>  If a set of names really is all equivalent, wouldn't it be better in the
>> long run for people to configure the set once rather than once per server?
>
> I think we've been round this loop and determined that for most/many
> applications there is /still/ manual configuration (see SSL cert DN
> for example).

If we're serious about names being equivalent, browsers should be able to 
take the name in an SSL cert, and check in the DNS to see if it's 
equivalent to the name it's using.  If we believe in DNSSEC this shouldn't 
be a security issue.

Yes, this is a lot more work than some DNS tweak that makes everything 
work, but if the DNS tweak existed, we would already have found it.

Regards,
John Levine, johnl@iecc.com, Primary Perpetrator of "The Internet for Dummies",
Please consider the environment before reading this e-mail. http://jl.ly
_______________________________________________
dnsext mailing list
dnsext@ietf.org
https://www.ietf.org/mailman/listinfo/dnsext