Re: Extending UPDATE to add/remove zones
"Hosnieh Rafiee" <[email protected]>
| Newsgroups | gmane.ietf.dnsext |
|---|---|
| Message-ID | <[email protected]> |
Sorry I forgot to submit it to the list ... >No Hosnieh I'm not falling for that. If you think there is any overlap/conflict/interaction between my proposed work and the cga-tsig draft then please >identify it and I will address it. >To be clear, since it appears to me that you might not have understood, the only idea I am floating around TSIG is that a DNSKEY record is given to a >nameserver with the intention that is should use to authenticate (via TSIG) a zone transfer request for a new zone that it is asked to serve as a slave. I am attempting to rephrase my question. Correct me if I am wrong... I think DNSKEY is for DNSSEC and not for TSIG. TSIG uses shared secret and it is added to DNS configuration file (isn't stored in any record in database) . dissimilar to a part of DNSSEC it is not public key cryptography. This means that you cannot add the shared secret in DNSKEY for authentication. Security problem... TSIG might use TKEY which is different than DNSKEY. Secondly, I guess addressing TSIG here does not really make sense as you are not fully addressing security but you're planning to make the DNS update more efficient. So, I suggest that you only think about making the Update more efficient and let other approaches like other RRs TSIG, cga-tsig secure your approach. Thanks, Best, Hosnieh _______________________________________________ dnsext mailing list [email protected] https://www.ietf.org/mailman/listinfo/dnsext