Re: Implementing DANE for qmail

Manvendra Bhangui <[email protected]> Mon, 10 Apr 2017 10:06:11 +0530
Newsgroups gmane.mail.qmail.general
Message-ID <CAOqj+1Md_SJOjW7Eet4uJG9Q5ydVd88nwBRhLi__2yKO7yNcWw@mail.gmail.com>
On 9 April 2017 at 23:37, Erwin Hoffmann <[email protected]> wrote:

>> It
>> is MUST that the zone which has a TLSA RR must be signed by DNSSEC and
>> the applications which query the domain for TLSA RR validation should
>> use a DNSSEC aware resolver. This is where I am confused. Do all
>> resolver setup support DNSSEC?
>
> No. qmail-remote uses a stub-resolver and DNSSEC/TLS validation could/should be done by means of a proxy.
>

Found this and it was helpful to me in understanding
http://wiki.halon.io/DANE


> PS. Within s/qmail Cert Pinning is supported which is great on peer-2-peer base, but of course does not scale like TLSA.
>

Will look forward to your implementation. BTW, another question. Do
folks still use djbdns? There is a DNSSEC patch for djbdns -
http://www.tinydnssec.org/ and has been implemented below

https://blog.ploetzli.ch/2014/tinydns-dnssec/


-- 
Regards Manvendra - http://www.indimail.org
GPG Pub Key
http://pgp.mit.edu:11371/pks/lookup?op=get&search=0xC7CBC760014D250C