Re: Registry lock - setting statuses on hosts
Marc Groeneweg <[email protected]> Wed, 16 Oct 2013 07:59:22 +0000
| Newsgroups | gmane.ietf.provreg |
|---|---|
| Message-ID | <[email protected]> |
>> There is a scenario where you hijack the registrar, and change the >> DNSSEC key material at the registry to DOS the victim. Or delete the >> DNSSEC key material so you can do cache pollution. > >Having the private key at the domain holder would actually prevent that. Is that true Jaap? I don't think so. The villain makes his own private key, and makes sure he gets a real secure delegation to his own infrastructure, hijacking the domain name and still have DNSSEC validation in place. I guess it's all about timing isn't it? Regards, Marc _______________________________________________ provreg mailing list [email protected] https://www.ietf.org/mailman/listinfo/provreg