Re: Extending UPDATE to add/remove zones
Jay Daley <[email protected]>
| Newsgroups | gmane.ietf.dnsext |
|---|---|
| Message-ID | <[email protected]> |
On 17/10/2013, at 10:35 AM, Hosnieh Rafiee <[email protected]> wrote: >> I'm not sure how that is relevant - perhaps you could explain? And to > answer your question - I have no idea at all. > > Cga-tsig addresses secure authentication during different scenarios such as > FQDN, zone transfer, resolver to client, resolver to authoritative servers, > etc. > It uses cga parameters as a means for this authentication. CGA proves the > address ownership of nodes by finding a binding between the nodes' public > key and its iP address. Cga-tsig adds cga parameters to the otherdata > section of TSIG RDATA. So, it is quite different than TSIG but it will be a > new algorithm in tsig. > http://tools.ietf.org/html/draft-rafiee-intarea-cga-tsig-06 > > - What is the difference between your proposed work with cga-tsig draft and > tsig? What is the overlap between your proposed work and cga-tsig draft? No Hosnieh I'm not falling for that. If you think there is any overlap/conflict/interaction between my proposed work and the cga-tsig draft then please identify it and I will address it. To be clear, since it appears to me that you might not have understood, the only idea I am floating around TSIG is that a DNSKEY record is given to a nameserver with the intention that is should use to authenticate (via TSIG) a zone transfer request for a new zone that it is asked to serve as a slave. Jay -- Jay Daley Chief Executive .nz Registry Services (New Zealand Domain Name Registry Limited) desk: +64 4 931 6977 mobile: +64 21 678840 linkedin: www.linkedin.com/in/jaydaley _______________________________________________ dnsext mailing list [email protected] https://www.ietf.org/mailman/listinfo/dnsext