Re: secdns draft

Edward Lewis <[email protected]>
Newsgroups gmane.ietf.provreg
Message-ID <a06200707bf8431f459a5@[192.35.167.157]>
At 21:02 +0200 10/25/05, Klaus Malorny wrote:

>Thanks for the clarification. I thought the most simple solution to revoke a
>key is to remove it from the zone, as it would break the chain of trust also.
>But I have to admit that I am not yet fully aware of the effects of 
>the various
>caching mechanisms on the time a resolver can falsely assume the correctness
>of a revoked key. I have to check that.

One issue I omitted is that there is also the possibility of an 
illicit replay attack.  Besides caches, if the attacker copies the DS 
set before the key compromise is known, the attacker can poison 
caches with the set as long as the signature is valid.  So even 
pulling the (DS record of the) key from the parent zone isn't 
sufficient for revocation.

Short of having an explicit revocation list in DNS (never happen), we 
have this problem.
-- 
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
Edward Lewis                                                +1-571-434-5468
NeuStar

True story:
Only a routing "expert" would fly London->Minneapolis->Dallas->Minneapolis
to get home from a conference.  (Cities changed to protect his identity.)
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.