Re: Authenticated denial of existence...

Dave Lawrence <[email protected]> Wed, 20 Nov 2013 12:53:22 -0500
Newsgroups gmane.ietf.dnsext
Message-ID <[email protected]>
Tony Finch writes:
> > https://datatracker.ietf.org/doc/draft-gieben-auth-denial-of-existence-dns/
> 
> A really nice and helpful document.

Agreed.  Really well put-together.  I do like the previously mentioned
ideas of including a bit about RFC 4470 and a few short words on
alternatives to managing the nsec3 hash space (like Kaminsky's).
Appendix is fine to not disrupt the flow, and it probably doesn't
really need more than a paragraph or so for each.

Section 3[.0] should probably elaborate on this:

   When you are querying a name server for a record that actually
   exists, a man-in-the-middle may replay that generic denial record
   and it would be impossible to tell whether the response was genuine
   or spoofed.

especially when later on 3.2 says this:

   Therefore, the RRSIG's RDATA include a validity period (not visible
   in the zone above), so that an attacker cannot replay this NXDOMAIN
   response for "c.example.org" forever.

which could easily leave the reader wondering, "so why doesn't having
a validity period on a generic denial record adequately address this?"

I realize the answer is obvious to us, but it isn't obvious in the
document, which is meant to be accessible by people outside the
security sphere.

Maybe this subtle would work?  I'm not entirely sure how much it does
help, but does start to point in the right direction.

   When you are querying a name server for any record that actually
   exists, a man-in-the-middle could replay that generic denial record
   that is not limited in its scope and it would be impossible to tell
   whether the response was genuine or spoofed.
_______________________________________________
dnsext mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/dnsext