Implementing DANE for qmail
Manvendra Bhangui <[email protected]> Sun, 9 Apr 2017 21:22:00 +0530
| Newsgroups | gmane.mail.qmail.general |
|---|---|
| Message-ID | <CAOqj+1NaQy0t5xsvUXa6YP4xN4XT0CqTZ0=ckSPqsBUZ-=mkcg@mail.gmail.com> |
I have been thinking about this and have followed this document https://www.ietf.org/mail-archive/web/dane/current/pdfk2DbQF0Oxs.pdf What I have understood is this For Domain owners publish a TLSA Resource Record (RR) and enforce your servers to use TLS. For clients query the TLSA RR and then decide to connect or not. This will require modification to qmail-remote. As specified in the DANE protocol RFC, the TLSA RR resulting from a DNS Query must be validated by DNSSEC. It is MUST that the zone which has a TLSA RR must be signed by DNSSEC and the applications which query the domain for TLSA RR validation should use a DNSSEC aware resolver. This is where I am confused. Do all resolver setup support DNSSEC? Is there anyone working on this? If yes, how difficult would this be to implement? -- Regards Manvendra - http://www.indimail.org GPG Pub Key http://pgp.mit.edu:11371/pks/lookup?op=get&search=0xC7CBC760014D250C