[Hipsec-rg] Re: Native HIP API questions in the hipsec-rg meeting

shep@alum.mit.edu (Tim Shepard) Mon, 16 August 2004 09:28 UTC

From: shep@alum.mit.edu (Tim Shepard)
Date: Mon Aug 16 09:28:01 2004
Subject: [Hipsec-rg] Re: Native HIP API questions in the hipsec-rg meeting
In-Reply-To: Your message of Mon, 16 Aug 2004 15:48:20 +0300. <Pine.GSO.4.58.0408161501130.1778@kekkonen.cs.hut.fi>
Message-ID: <E1BwiUq-00079b-00@alva.home>

> > Tim Shepard:  What if no DNS?  Nervous about building in dependencies on
> > DNS.
> >
> > Julien:  use /etc/hosts.  Can fall back to opportunistic mode too.
> 
> The other alternative for DNS is the DHT, but it remains to be seen if we
> ever get there. In the mean time, we should rely on DNS, as there are no
> real alternatives currently available.
> 
> Maybe the resolver should should support DHT queries too. With a new
> resolver, this should not be a problem. I'll have to look at this topic
> when I get my hands on a DHT DNS replacement implementation...
> 


What I mean is that it should be possible to install and use HIP in a
meaningful way without requiring that you get your site administrator
to update the DNS servers.  (If additional records in the DNS enhance
the usefulness and/or security of HIP, that's OK.)

I don't think SSH would have ever seen much deployment if in order to
use it you would have had to get special SSH keys distributed by the
DNS servers.   That would have made it as difficult to install and use
as the kerberos-based encrypted rlogin (which I was using for many
years until ssh came along and made it so much easier).

The web would have never gotten very far if a new record type had to
be put in the DNS to support http.

			-Tim Shepard
			 shep@alum.mit.edu