Re: [dnsext] we need help to make names the same, was draft-yao-dnsext-identical-resolution-02 comment

Phillip Hallam-Baker <hallam@gmail.com> Wed, 23 February 2011 19:59 UTC

Return-Path: <dnsext-bounces@ietf.org>
X-Original-To: namedroppers-archive-gleetwall6@lists.ietf.org
Delivered-To: ietfarch-namedroppers-archive-gleetwall6@core3.amsl.com
Received: from [127.0.0.1] (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id BD3793A6A57; Wed, 23 Feb 2011 11:59:43 -0800 (PST)
X-Original-To: dnsext@core3.amsl.com
Delivered-To: dnsext@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id 863443A6A57 for <dnsext@core3.amsl.com>; Wed, 23 Feb 2011 11:59:42 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -3.562
X-Spam-Level:
X-Spam-Status: No, score=-3.562 tagged_above=-999 required=5 tests=[AWL=0.036, BAYES_00=-2.599, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_LOW=-1]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 1Oc1OWgUxQmK for <dnsext@core3.amsl.com>; Wed, 23 Feb 2011 11:59:41 -0800 (PST)
Received: from mail-bw0-f44.google.com (mail-bw0-f44.google.com [209.85.214.44]) by core3.amsl.com (Postfix) with ESMTP id 50E2D3A6A3A for <dnsext@ietf.org>; Wed, 23 Feb 2011 11:59:41 -0800 (PST)
Received: by bwz13 with SMTP id 13so548925bwz.31 for <dnsext@ietf.org>; Wed, 23 Feb 2011 12:00:28 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=gamma; h=domainkey-signature:mime-version:in-reply-to:references:date :message-id:subject:from:to:cc:content-type; bh=GJJaqDzkwAmzXigzJII4TH0Yuq4WHPUkRgc353DfyqY=; b=BQte9m6K1I8UWxSbYTo6Cu98qH0yRVyUnbRESPecL/t6EtIXkGFxt59EJlpxaLV21r IU9ZNrlLhVd8fhDdtXBoh/0k4YVx4AVoD8yvC4u//ucaEhsM/IohXiHfJa1NVnR87DSo R9dYytDQAockPAv/uZ8RPG81uUN1KGV58GSvM=
DomainKey-Signature: a=rsa-sha1; c=nofws; d=gmail.com; s=gamma; h=mime-version:in-reply-to:references:date:message-id:subject:from:to :cc:content-type; b=TEi0nLr8Qg9NWvQrW68S4R+yNdHlEqIVfhw02T3EuKlcWvHLfbhQ7qA4oDAZsegAc2 7jnt9c1vlTg5bjOV6Tf2XfVf16QUyUf/dYMzMZbwzVAq4ceLyOtZVLmJGgEHsecW0Hz9 I7tJhjkQgP6tB+ojjdu9Z0WzJsJSu3UowRNfE=
MIME-Version: 1.0
Received: by 10.204.24.135 with SMTP id v7mr3772436bkb.99.1298491227991; Wed, 23 Feb 2011 12:00:27 -0800 (PST)
Received: by 10.204.14.139 with HTTP; Wed, 23 Feb 2011 12:00:27 -0800 (PST)
In-Reply-To: <alpine.LSU.2.00.1102231029260.27602@hermes-1.csi.cam.ac.uk>
References: <20110216165921.GW96213@shinkuro.com> <3B90ED2E-980D-4B01-889F-447D66D0B58D@insensate.co.uk> <20110216174011.GZ96213@shinkuro.com> <20110218143653.GC84482@bikeshed.isc.org> <20110218151209.GF66684@shinkuro.com> <4D5EEE09.4080405@dougbarton.us> <20110218222950.GL74065@shinkuro.com> <4D5F270F.20401@abenaki.wabanaki.net> <199C7B2B4228461FB024E59A990DB46D@ics.forth.gr> <4D641DB6.4090705@necom830.hpcl.titech.ac.jp> <20110222205617.GS53815@shinkuro.com> <4D64489B.7020901@necom830.hpcl.titech.ac.jp> <713D992A-1DB9-4F72-9D18-8E923AD51D8D@icsi.berkeley.edu> <AANLkTikf2ixw7JkxQiRBobv-seYnaYS0E3G8TboosnA=@mail.gmail.com> <alpine.LSU.2.00.1102231029260.27602@hermes-1.csi.cam.ac.uk>
Date: Wed, 23 Feb 2011 15:00:27 -0500
Message-ID: <AANLkTin6-mXBeKC_TzgvWUaCyxKfeZxTK1BQvXtpwuCN@mail.gmail.com>
From: Phillip Hallam-Baker <hallam@gmail.com>
To: Tony Finch <dot@dotat.at>
Cc: dnsext@ietf.org
Subject: Re: [dnsext] we need help to make names the same, was draft-yao-dnsext-identical-resolution-02 comment
X-BeenThere: dnsext@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: DNS Extensions working group discussion list <dnsext.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/dnsext>, <mailto:dnsext-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/dnsext>
List-Post: <mailto:dnsext@ietf.org>
List-Help: <mailto:dnsext-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dnsext>, <mailto:dnsext-request@ietf.org?subject=subscribe>
Content-Type: multipart/mixed; boundary="===============1139669737=="
Sender: dnsext-bounces@ietf.org
Errors-To: dnsext-bounces@ietf.org

On Wed, Feb 23, 2011 at 5:30 AM, Tony Finch <dot@dotat.at> wrote:

> On Tue, 22 Feb 2011, Phillip Hallam-Baker wrote:
>
> > If you are going to do [online signing], you might as well do a key
> > exchange inline as well as we do in TLS. One key exchange can then be
> > leveraged across multiple connections using kerberos style tickets (see
> > DPLS for an example).
>
> That gives you channel security whereas DNSSEC gives you data origin
> authentication. They are not the same things.


True, but data origin authentication is probably the wrong model for a DNS
security scheme.

If we are going to consider changing the model of DNSSEC, which is what
moving to online signatures would entail, then the whole architecture is
back on the table.



-- 
Website: http://hallambaker.com/
_______________________________________________
dnsext mailing list
dnsext@ietf.org
https://www.ietf.org/mailman/listinfo/dnsext