[116522] in North American Network Operators' Group

home help back first fref pref prev next nref lref last post

Re: dnscurve and DNS hardening, was Re: Dan Kaminsky

daemon@ATHENA.MIT.EDU (Florian Weimer)
Thu Aug 6 03:37:49 2009

To: Naveen Nathan <naveen@calpop.com>
From: Florian Weimer <fweimer@bfk.de>
Date: Thu, 06 Aug 2009 07:37:01 +0000
In-Reply-To: <20090806044533.GN30683@armakuni.lastninja.net> (Naveen Nathan's
	message of "Wed\, 5 Aug 2009 21\:45\:34 -0700")
Cc: nanog@nanog.org
Errors-To: nanog-bounces+nanog.discuss=bloom-picayune.mit.edu@nanog.org

* Naveen Nathan:

> I'll assume the cipher used for the lasting secret keys is interchangeabl=
e.

Last time I checked, even the current cryptographic algorithms weren't
specified.  It's unlikely that there is an upgrade path (other than
stuffing yet another magic label into your name server names).

--=20
Florian Weimer                <fweimer@bfk.de>
BFK edv-consulting GmbH       http://www.bfk.de/
Kriegsstra=DFe 100              tel: +49-721-96201-1
D-76133 Karlsruhe             fax: +49-721-96201-99


home help back first fref pref prev next nref lref last post