Re: Install DNS mappings based on TLS/IPsec?
Iljitsch van Beijnum <[email protected]>
| Newsgroups | gmane.ietf.multi6 |
|---|---|
| Message-ID | <[email protected]> |
On 4-jul-04, at 10:43, Brian E Carpenter wrote: > Are you suggesting that the multi6 solution should have a strict > dependency on using TLS or IPSEC? Certainly not. I'm saying two things: - if the DNS doesn't work, discover information that would normally be in the DNS through the TLS or IKE negotiation, and - the DNS is often insecure, so let the TLS or IKE derived information override it to increase security But if TLS/IPsec aren't used, the information is taken from the DNS.