Re: Extending UPDATE to add/remove zones
Jay Daley <[email protected]>
| Newsgroups | gmane.ietf.dnsext |
|---|---|
| Message-ID | <[email protected]> |
On 17/10/2013, at 11:12 AM, "Hosnieh Rafiee" <[email protected]> wrote: > Sorry I forgot to submit it to the list ... > >> No Hosnieh I'm not falling for that. If you think there is any > overlap/conflict/interaction between my proposed work and the cga-tsig draft > then please >identify it and I will address it. > >> To be clear, since it appears to me that you might not have understood, the > only idea I am floating around TSIG is that a DNSKEY record is given to a >> nameserver with the intention that is should use to authenticate (via TSIG) > a zone transfer request for a new zone that it is asked to serve as a slave. > > I am attempting to rephrase my question. Correct me if I am wrong... I think > DNSKEY is for DNSSEC and not for TSIG. TSIG uses shared secret and it is > added to DNS configuration file (isn't stored in any record in database) . > dissimilar to a part of DNSSEC it is not public key cryptography. This means > that you cannot add the shared secret in DNSKEY for authentication. Security > problem... TSIG might use TKEY which is different than DNSKEY. Yes it probably ought to be TKEY since this is what it is specifically designed for and not a DNSKEY but DNSKEY is so much simpler so I was just trying it on ... > Secondly, I guess addressing TSIG here does not really make sense as you are > not fully addressing security but you're planning to make the DNS update > more efficient. So, I suggest that you only think about making the Update > more efficient and let other approaches like other RRs TSIG, cga-tsig secure > your approach. You've misunderstood why the TSIG key appears in this message. I am investigating adding new functionality to UPDATE and part of that new functionality requires the transmission of a TSIG key as data inside the packet, for the receiver to use elsewhere. This TSIG key is not used in this transaction. Jay -- Jay Daley Chief Executive .nz Registry Services (New Zealand Domain Name Registry Limited) desk: +64 4 931 6977 mobile: +64 21 678840 linkedin: www.linkedin.com/in/jaydaley _______________________________________________ dnsext mailing list [email protected] https://www.ietf.org/mailman/listinfo/dnsext