Re: Authenticated denial of existence...
"Jiankang Yao" <[email protected]> Wed, 20 Nov 2013 14:59:40 +0800
| Newsgroups | gmane.ietf.dnsext |
|---|---|
| Message-ID | <[email protected]> |
good writing of this draft.
I am interested the following text in section 3:
" 2. The DNS packet header is not signed. This means that a "status:
NXDOMAIN" can not be trusted. In fact the entire header may be
forged, including the AD bit (AD stands for Authentic Data, see
RFC 3655 [RFC3655]), which may give some food for thought;
"
so if the resolver is attacked, such as hacking the "status" field or the whole header, what will happen?
Jiankang Yao
From: Ted Lemon
Date: 2013-11-20 11:30
To: Group
Subject: [dnsext] Authenticated denial of existence...
Is this on anyone's radar? What are your thoughts about it?
https://datatracker.ietf.org/doc/draft-gieben-auth-denial-of-existence-dns/
_______________________________________________
dnsext mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/dnsext
_______________________________________________
dnsext mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/dnsext