cga-tsig new version - clarification of problem statement

"Hosnieh Rafiee" <[email protected]>
Newsgroups gmane.ietf.dnsext,gmane.ietf.int
Message-ID <[email protected]>
Hello,

I uploaded new version of cga-tsig, I tried to clarify the points and
improved the problem statement. I improved the problem statement section and
also modified the other section. For example, In the case of adding the IP
addresses of other DNS servers manually to the configuration file (DNS
update) or the case where you want to authenticate the resolver (you already
know the IP address of the resolver via a DHCP server or an option in a RA
message), the authentication is based solely on the source IP address. So it
is possible for someone to spoof this IP address and poison the client's DNS
cache. Of course it is possible to use it during a zone transfer as the
authentication is again based on the source IP address if no security
mechanisms are used. If it is used, then there is the other problem of
dealing with the configuration of DNSSEC and TSIG, or shared secret leakage
in TSIG. The purpose of CGA-TSIG is to eliminate these problems and to
reduce the number of manual steps needed to carry out a configuration. I
also explained in the document the case where the DNS server does not
support SeND. So there are two options; it can either generate the CGA
parameters by using any external script and then configure the IP address
and use it as a means for further authentication, or it can generate the key
pairs itself and skip the CGA verification step during the verification
process, which is not secure in PTR or source IP address verification. 

http://tools.ietf.org/html/draft-rafiee-intarea-cga-tsig  

I hope that this clarifies the draft. I have tried to respond to your
concerns and I hope that with this version we can move forward.

Thanks,
Best,
Hosnieh
P.S. Sorry if any of you received this message twice.

_______________________________________________
dnsext mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/dnsext
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.