Re: please review - DNS data integrity and confidentiality

Carsten Strotmann <[email protected]> Tue, 04 Mar 2014 15:07:08 +0100
Newsgroups gmane.ietf.dnsext
Message-ID <[email protected]>
Hello Hosnieh,

(I've only responding on DNSEXT, if one of the other lists is more
approriate, let me know).

Hosnieh Rafiee <[email protected]> writes:

>
> CGA-TSIG (http://tools.ietf.org/html/draft-rafiee-intarea-cga-tsig ) will be

I've read your draft and attended the INTAREA session today. I'm at this
moment have not a full understanding of the concept, but it is
interesting and there is some need.

Some questions:

11.1 Generation of secret key (Page 17)

> It is possible to use the current DNSKEY RR (RFC 3757) to send the
> public key of the DNS server.

My understanding of the DNSKEY RR is that (at least in the context of
DNSSEC) the DNSKEY RR is bound to a specific DNS zone, but not to a DNS
server. The draft indicates that the DNSKEY is somehow used to
identify/authenticate the DNS server. Which DNSKEY record would that be
(out of which zone)?

> It encrypts this
>   secret key using the DNS server public key. This allows only the DNS
>   server to decrypt this secret key.

This implies some private key being online on the DNS server. Which
private key would that be?

11.2 DNS message generation (Page 17)

> The node MUST encrypt all DNS message sections that required
>   protections using the secret key generated in last section and AES
>   symmetric algorithm. 

It is probably not good to hardcode an particular cipher algorithm
(AES).

Probably more questions will come up once I read the draft again and
work with the proof-of-concept implementation.

Best regards

Carsten Strotmann

-- 
Sent with my mu4e

_______________________________________________
dnsext mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/dnsext