Re: dns.c modification patch for getting TLSA RR records
Erwin Hoffmann <[email protected]> Sun, 27 May 2018 22:15:03 +0200
| Newsgroups | gmane.mail.qmail.general |
|---|---|
| Message-ID | <[email protected]> |
Hi, > Am 26.05.2018 um 15:57 schrieb Manvendra Bhangui <[email protected]>: > > On 26 May 2018 at 18:39, Erwin Hoffmann <[email protected]> wrote: > > Apart from that: The use of TLSA records (and perhaps CAA) together with CurveDNS (given it's lookup) is certainly as 'safe' as with DNSSEC, though the RFC just require the later. > > Regards. > > > Thanks for the pointer. I will take a look at curvedns. Is it the one at http://curvedns.on2it.net/ ? Yeah, you can find more interesting implementations here: https://www.fehcom.de/ipnet/djbdnscurve6.html Apart from those, I hope to finish 'dbbdnscurve6' within the next weeks: - entire IPv6 capability. - rbldns can be used to flag IPv6 addresses. Regards. --eh. > Dr. Erwin Hoffmann | FEHCom | http://www.fehcom.de | PGP Key-Id 7E4034BE
signature.asc
(application/pgp-signature, 833 B)
-----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE91BSzimpKm1LIXVDg/z5IO4Az2UFAlsLEccACgkQg/z5IO4A z2U1tw/+L8lbwW+hfR2WQYlS5RIznPDS69e7xVBTY1AWOX50P/LAXLP4+ZoVUJGx OkxBS644OybEDc/5r6GJVaQ7oEwGmiMBbU9EOeWgrN+M4u/GSphSB9FCXl0lvEXl uu/oZ1mJkjkvZU2B2xLC9qAnS3DM8assa4ECoDOk5bFCSmtL8UZrf3ETLJkdepy+ bilbfsMEAM9Gw4+W1+QdV6jbEufr/3LIvvYgw7y7dbDMIm7j7Sy1QnhtZRuH8iob x+1i/OVSyFf6to3jQwPC824VeCda96pzX2g1o2+Zznuwtvtb3StotkBbU4qQshpT 9kxPuEOP4qPe7UWBCdnEjsBPtReIToO3ySCXzZblP6SSK13rGfWhtUnDeCfWPBxk PqZjz9xelyEZWhQJxdtDAZv0BuudUathld1tIzCD8vVpLrx8sc5dMwSDBnfjWfLt D55hdwRCoCk7tUTuKCazwt+zn5fdw3PczfiNZucCnZIBlPwbsqkBKbLdjXEtR/Vm +EnKKAUL2teVQLUx6L0c/H5yXMbjTGsYAHsaYoSZqbAv5y2fdq/nLDGl707LjGPR cVSsDq61hFrzUUv/DZtwYZZ8XvNujkWp9VbS/69cL87QVGfMxP4m1S4did+12FH1 pTyzQpCowQ8ArP0uYPAnSv2eusjNBS/+y0W2HtgTD/pZ0h3pV14= =7Pk0 -----END PGP SIGNATURE-----