Re: New RRtype "KREALM" in draft-vanrein-dnstxt-krb1-02.txt

Rick van Rein <[email protected]> Fri, 04 Sep 2015 08:38:23 +0200
Newsgroups gmane.ietf.dnsext
Message-ID <[email protected]>
Hi Mark / others,

Thanks for your reading & commenting!

As for base64, I was also considering to adopt the hexadecimal notation
used for Unknown RRtypes [RFC 3579]; ASN.1 data is quite readable in
hexdump form, and absolutely not in base64 form.

Do you have any ideas if that would be considered silly or awkward?

> If you only want the AD bit to be returned then set AD=1 in the
> query not DO=1. See RFC 6840. Modern versions of DiG do this by
> default. If the resolver or the path to it is not trusted then you
> need to specify DO=1 and perform local validation as you can't rely
> on the AD bit.

Thanks for pointing that out, I was indeed following older specs. 
Changed for -03:

   To give one possible implementation, a Kerberos client may send DNS
   queries with the Authentic Data (AD) bit set to enable DNSSEC
   [Section 5.7 of [RFC6840]], and require that the Authenticated Data
   bit is set in the response to indicate [RFC3655] the Secure state for
   answer and authority sections of the response.  When the DNS traffic
   to and from the validating resolver is protected, for instance
   because that resolver is reached over a loopback interface, then the
   Kerberos client has implemented the requirements for Secure use of
   the answer and authority sections in DNS responses.

> Don't put the base64 in quotes.

I changed the examples accordingly in -03.

> Do specify that the base64 encoding may be broken up by white space
> and may be over multiple lines using the standard DNS mechanisms
> for doing this. There is no need for it to be a single lexographic
> token. This needs to be clear as registrars stuffed up DS handling
> by only coding for a single lexographic token in DS despite it being
> specified as allowing multiple tokens. Add some examples where the
> base64 is split into multiple tokens.
>
Added to -03

   [...]  The base64-represented data may be interspersed with white
   space, including even line breaks if the usual DNS zone file notation
   with parenthesis is used.

I also demonstrated the line breaks in an example:

   www.example.com.  IN KREALM ( ME8xTTAOFgdzZXJ2aWNlDANmdHAwDxYH
   c2VydmljZQwESFRUUDAUFgVyZWFsbQwL RVhBTVBMRS5DT00wFBYFcmVhbG0MC0VY
   QU1QTEUuT1JH )


Thanks!
 -Rick

_______________________________________________
dnsext mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/dnsext