Re: DNSSEC Trust Anchor Repository
Dean Anderson <[email protected]>
| Newsgroups | gmane.network.djbdns |
|---|---|
| Message-ID | <[email protected]> |
No one could explain what regulatory approval there was for signing .org TLD. The .org TLD appears to be closely controlled by Cerf, Crocker, Vixie, Joffe et al. I don't think it can be considered as evidence of DNSSEC 'gaining traction' for that reason. I understand that the NTIA has refused to allow the root to be signed, because of a number of serious problems with DNSSEC. My comments on DNSSEC, including some on the Kaminsky/Vixie scam are here: http://www.ntia.doc.gov/dns/comments/comment027.pdf There is no need for secure DNS in any case. TLS or similar is always needed to protect from Man-in-the-middle attacks, and TCP is already invulnerable to blind (not-in-the-middle) attacks. DNSSEC solves no problem and adds a number of problems, including two serious DDoS problems. As other DNS experts have pointed out (e.g. Masataka Ohta), DNSSEC is not secure end-to-end so it fails at what it set out to do. I don't think DNSSEC will ever be approved for use, so there is little point in adding support in dnscache or tinydns. --Dean On Tue, 23 Jun 2009, fchan wrote: > Hi, > I double that. I haven't heard anyone on this issue since DNSSEC is > slowly gaining ground and we on the .org already have been signed > with DNSSEC. > http://mailman.nanog.org/pipermail/nanog/2009-June/011006.html > http://pir.org/index.php?db=content/Website&tbl=ORG_Advantage&id=2 > http://www.pcworld.com/businesscenter/article/165916/security_tightened_for_org_domain.html > > Regards, > Frank > > >Hello, > > > >is there a way to support this with tiny ? > > > >https://itar.iana.org/ > > > >best regards, > > > > M.Schwarz > > > -- Av8 Internet Prepared to pay a premium for better service? www.av8.net faster, more reliable, better service 617 344 9000