Re: [OT: DNSCurve] Resolvers w/o key -> HMAC Proposal

Michael Sierchio <[email protected]>
Newsgroups gmane.network.djbdns
Message-ID <[email protected]>
Erwin Hoffmann wrote:
> Good morning,
> 
> since there is no official discussion list on DNSCurve I try my question
> here.
> 
> Current: DNSCurve requires that both the DNSCurve Sever as well
> Responder do encrypt their DNS messages with the public key of the peer.
> In fact, DNSCurve builds it's own infrastructure on top of public DNS
> and aside from DNSSec.
> 
> Question: Wouldn't it be enough if the the DNSCurve Server has a Key ?

No.

ECDH is a variant of Diffie-Hellman, and requires the use of an
implicit shared secret - the result of an operation using your
private key and the other party's public key.

In the case of the server, the binding of identity to pubkey is
accomplished by encoding the key in the FQDN.

An anonymous user could create an ad hoc keypair, and send the
public key along with a proof-of-possession (some operation
using the implicit shared secret), and the operation works fine.

But no encryption or decryption (hence, no authentication) is
possible without each party having a keypair.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.