cga-tsig new version - clarification of problem statement
"Hosnieh Rafiee" <[email protected]>
| Newsgroups | gmane.ietf.dnsext,gmane.ietf.int |
|---|---|
| Message-ID | <[email protected]> |
Hello, I uploaded new version of cga-tsig, I tried to clarify the points and improved the problem statement. I improved the problem statement section and also modified the other section. For example, In the case of adding the IP addresses of other DNS servers manually to the configuration file (DNS update) or the case where you want to authenticate the resolver (you already know the IP address of the resolver via a DHCP server or an option in a RA message), the authentication is based solely on the source IP address. So it is possible for someone to spoof this IP address and poison the client's DNS cache. Of course it is possible to use it during a zone transfer as the authentication is again based on the source IP address if no security mechanisms are used. If it is used, then there is the other problem of dealing with the configuration of DNSSEC and TSIG, or shared secret leakage in TSIG. The purpose of CGA-TSIG is to eliminate these problems and to reduce the number of manual steps needed to carry out a configuration. I also explained in the document the case where the DNS server does not support SeND. So there are two options; it can either generate the CGA parameters by using any external script and then configure the IP address and use it as a means for further authentication, or it can generate the key pairs itself and skip the CGA verification step during the verification process, which is not secure in PTR or source IP address verification. http://tools.ietf.org/html/draft-rafiee-intarea-cga-tsig I hope that this clarifies the draft. I have tried to respond to your concerns and I hope that with this version we can move forward. Thanks, Best, Hosnieh P.S. Sorry if any of you received this message twice. _______________________________________________ dnsext mailing list [email protected] https://www.ietf.org/mailman/listinfo/dnsext