Re: Authenticated denial of existence...

Tony Finch <[email protected]> Mon, 25 Nov 2013 15:43:56 +0000
Newsgroups gmane.ietf.dnsext
Message-ID <[email protected]>
Miek Gieben <[email protected]> wrote:

> Matthijs and I added an extra appendix to cover on-line signing and
> made some tweaks to the rest of the text.

Looks good.

A point I just noticed in section 3 which I think could do with
elaborating:

      Given all these troubles, why didn't the designers of DNSSEC go
      for the (easy) route and allowed for on-line signing?  Well, at
      that time (pre 2000), on-line signing was not feasible with the
      then current hardware.  Keep in mind that the larger servers get
      between 2000 and 6000 queries per second (qps), with peaks up to
      20,000 qps or more.  Scaling signature generation to these kind of
      levels is always a challenge.  Another issue was (and is) key
      management, for on-line signing to work you need access to the
      private key(s).  This is considered a security risk.

I think it is worth saying that online signing makes it difficult to have
third party secondary authoritative servers, since they would need a copy
of the private ZSK. With normal DNSSEC, even with a dynamically updated
zone, the private keys do not need to be on a publicly accessible machine.

Tony.
-- 
f.anthony.n.finch  <[email protected]>  http://dotat.at/
Forties, Cromarty: East, veering southeast, 4 or 5, occasionally 6 at first.
Rough, becoming slight or moderate. Showers, rain at first. Moderate or good,
occasionally poor at first.
_______________________________________________
dnsext mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/dnsext