Re: Authenticated denial of existence...

Miek Gieben <[email protected]> Wed, 20 Nov 2013 13:05:46 +0000
Newsgroups gmane.ietf.dnsext
Message-ID <[email protected]>
[ Quoting <[email protected]> in "Re: [dnsext] Authenticated denial o..." ]
> Ted Lemon <[email protected]> wrote:
> 
> > Is this on anyone's radar?   What are your thoughts about it?
> >
> > https://datatracker.ietf.org/doc/draft-gieben-auth-denial-of-existence-dns/
> 
> A really nice and helpful document.

Thanks.

> A suggestion:
> 
> It should discuss RFC 4470 Minimally Covering NSEC Records, and the
> related idea of NSEC3 "white lies" implemented by Dan Kaminsky's
> Phreebird. (I can't immediately find a good description of how the latter
> works.) Both these require on-demand synthesizing and signing of negative
> responses, whereas the mechanisms that Miek's draft currently covers are
> all designed for serving from a pre-signed zone file without requiring
> online private keys.

I'm not sure how far in the review process we actually are with this draft,
and adding text about this is a considerable effort. However I think it is
valuable to have text on this in this draft too.

Regards,

-- 
   Miek Gieben
_______________________________________________
dnsext mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/dnsext