Re: Authenticated denial of existence...
Miek Gieben <[email protected]> Wed, 20 Nov 2013 13:05:46 +0000
| Newsgroups | gmane.ietf.dnsext |
|---|---|
| Message-ID | <[email protected]> |
[ Quoting <[email protected]> in "Re: [dnsext] Authenticated denial o..." ] > Ted Lemon <[email protected]> wrote: > > > Is this on anyone's radar? What are your thoughts about it? > > > > https://datatracker.ietf.org/doc/draft-gieben-auth-denial-of-existence-dns/ > > A really nice and helpful document. Thanks. > A suggestion: > > It should discuss RFC 4470 Minimally Covering NSEC Records, and the > related idea of NSEC3 "white lies" implemented by Dan Kaminsky's > Phreebird. (I can't immediately find a good description of how the latter > works.) Both these require on-demand synthesizing and signing of negative > responses, whereas the mechanisms that Miek's draft currently covers are > all designed for serving from a pre-signed zone file without requiring > online private keys. I'm not sure how far in the review process we actually are with this draft, and adding text about this is a considerable effort. However I think it is valuable to have text on this in this draft too. Regards, -- Miek Gieben _______________________________________________ dnsext mailing list [email protected] https://www.ietf.org/mailman/listinfo/dnsext