Re: Authenticated denial of existence...
Tony Finch <[email protected]> Mon, 25 Nov 2013 15:43:56 +0000
| Newsgroups | gmane.ietf.dnsext |
|---|---|
| Message-ID | <[email protected]> |
Miek Gieben <[email protected]> wrote: > Matthijs and I added an extra appendix to cover on-line signing and > made some tweaks to the rest of the text. Looks good. A point I just noticed in section 3 which I think could do with elaborating: Given all these troubles, why didn't the designers of DNSSEC go for the (easy) route and allowed for on-line signing? Well, at that time (pre 2000), on-line signing was not feasible with the then current hardware. Keep in mind that the larger servers get between 2000 and 6000 queries per second (qps), with peaks up to 20,000 qps or more. Scaling signature generation to these kind of levels is always a challenge. Another issue was (and is) key management, for on-line signing to work you need access to the private key(s). This is considered a security risk. I think it is worth saying that online signing makes it difficult to have third party secondary authoritative servers, since they would need a copy of the private ZSK. With normal DNSSEC, even with a dynamically updated zone, the private keys do not need to be on a publicly accessible machine. Tony. -- f.anthony.n.finch <[email protected]> http://dotat.at/ Forties, Cromarty: East, veering southeast, 4 or 5, occasionally 6 at first. Rough, becoming slight or moderate. Showers, rain at first. Moderate or good, occasionally poor at first. _______________________________________________ dnsext mailing list [email protected] https://www.ietf.org/mailman/listinfo/dnsext