Re: Extending UPDATE to add/remove zones

"Hosnieh Rafiee" <[email protected]>
Newsgroups gmane.ietf.dnsext
Message-ID <[email protected]>
Sorry I forgot to submit it to the list ...

>No Hosnieh I'm not falling for that.  If you think there is any
overlap/conflict/interaction between my proposed work and the cga-tsig draft
then please >identify it and I will address it.  

>To be clear, since it appears to me that you might not have understood, the
only idea I am floating around TSIG is that a DNSKEY record is given to a
>nameserver with the intention that is should use to authenticate (via TSIG)
a zone transfer request for a new zone that it is asked to serve as a slave.

I am attempting to rephrase my question. Correct me if I am wrong... I think
DNSKEY is for DNSSEC and not for TSIG. TSIG uses shared secret and it is
added to DNS configuration file (isn't stored in any record in database) .
dissimilar to a part of DNSSEC it is not public key cryptography. This means
that you cannot add the shared secret in DNSKEY for authentication. Security
problem... TSIG might use TKEY which is different than DNSKEY. 
Secondly, I guess addressing TSIG here does not really make sense as you are
not fully addressing security but you're planning to make the DNS update
more efficient. So, I suggest that you only think about  making the Update
more efficient and let other approaches like other RRs TSIG, cga-tsig secure
your approach. 

Thanks,
Best, 
Hosnieh

_______________________________________________
dnsext mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/dnsext
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.