Re: please review - DNS data integrity and confidentiality
Carsten Strotmann <[email protected]> Tue, 04 Mar 2014 15:07:08 +0100
| Newsgroups | gmane.ietf.dnsext |
|---|---|
| Message-ID | <[email protected]> |
Hello Hosnieh, (I've only responding on DNSEXT, if one of the other lists is more approriate, let me know). Hosnieh Rafiee <[email protected]> writes: > > CGA-TSIG (http://tools.ietf.org/html/draft-rafiee-intarea-cga-tsig ) will be I've read your draft and attended the INTAREA session today. I'm at this moment have not a full understanding of the concept, but it is interesting and there is some need. Some questions: 11.1 Generation of secret key (Page 17) > It is possible to use the current DNSKEY RR (RFC 3757) to send the > public key of the DNS server. My understanding of the DNSKEY RR is that (at least in the context of DNSSEC) the DNSKEY RR is bound to a specific DNS zone, but not to a DNS server. The draft indicates that the DNSKEY is somehow used to identify/authenticate the DNS server. Which DNSKEY record would that be (out of which zone)? > It encrypts this > secret key using the DNS server public key. This allows only the DNS > server to decrypt this secret key. This implies some private key being online on the DNS server. Which private key would that be? 11.2 DNS message generation (Page 17) > The node MUST encrypt all DNS message sections that required > protections using the secret key generated in last section and AES > symmetric algorithm. It is probably not good to hardcode an particular cipher algorithm (AES). Probably more questions will come up once I read the draft again and work with the proof-of-concept implementation. Best regards Carsten Strotmann -- Sent with my mu4e _______________________________________________ dnsext mailing list [email protected] https://www.ietf.org/mailman/listinfo/dnsext