Re: Authenticated denial of existence...

Matthijs Mekking <[email protected]> Wed, 20 Nov 2013 14:40:11 +0100
Newsgroups gmane.ietf.dnsext
Message-ID <[email protected]>
I would like to add some more text about minimally covering records, but
I would not like to disturb the current flow of the document. In other
words, I suggest it to be either a short notice, or to appear as an
appendix.

Best regards,
  Matthijs


On 11/20/2013 02:05 PM, Miek Gieben wrote:
> [ Quoting <[email protected]> in "Re: [dnsext] Authenticated denial o..." ]
>> Ted Lemon <[email protected]> wrote:
>>
>>> Is this on anyone's radar?   What are your thoughts about it?
>>>
>>> https://datatracker.ietf.org/doc/draft-gieben-auth-denial-of-existence-dns/
>>
>> A really nice and helpful document.
> 
> Thanks.
> 
>> A suggestion:
>>
>> It should discuss RFC 4470 Minimally Covering NSEC Records, and the
>> related idea of NSEC3 "white lies" implemented by Dan Kaminsky's
>> Phreebird. (I can't immediately find a good description of how the latter
>> works.) Both these require on-demand synthesizing and signing of negative
>> responses, whereas the mechanisms that Miek's draft currently covers are
>> all designed for serving from a pre-signed zone file without requiring
>> online private keys.
> 
> I'm not sure how far in the review process we actually are with this draft,
> and adding text about this is a considerable effort. However I think it is
> valuable to have text on this in this draft too.
> 
> Regards,
> 

_______________________________________________
dnsext mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/dnsext