Re: Implementing DANE for qmail
Manvendra Bhangui <[email protected]> Mon, 10 Apr 2017 10:06:11 +0530
| Newsgroups | gmane.mail.qmail.general |
|---|---|
| Message-ID | <CAOqj+1Md_SJOjW7Eet4uJG9Q5ydVd88nwBRhLi__2yKO7yNcWw@mail.gmail.com> |
On 9 April 2017 at 23:37, Erwin Hoffmann <[email protected]> wrote: >> It >> is MUST that the zone which has a TLSA RR must be signed by DNSSEC and >> the applications which query the domain for TLSA RR validation should >> use a DNSSEC aware resolver. This is where I am confused. Do all >> resolver setup support DNSSEC? > > No. qmail-remote uses a stub-resolver and DNSSEC/TLS validation could/should be done by means of a proxy. > Found this and it was helpful to me in understanding http://wiki.halon.io/DANE > PS. Within s/qmail Cert Pinning is supported which is great on peer-2-peer base, but of course does not scale like TLSA. > Will look forward to your implementation. BTW, another question. Do folks still use djbdns? There is a DNSSEC patch for djbdns - http://www.tinydnssec.org/ and has been implemented below https://blog.ploetzli.ch/2014/tinydns-dnssec/ -- Regards Manvendra - http://www.indimail.org GPG Pub Key http://pgp.mit.edu:11371/pks/lookup?op=get&search=0xC7CBC760014D250C