[19097] in Kerberos_V5_Development
Re: Proposal for using NAPTR/URI records
daemon@ATHENA.MIT.EDU (Nico Williams)
Tue Feb 24 13:47:42 2015
MIME-Version: 1.0
In-Reply-To: <1424800004.13431.19.camel@willson.usersys.redhat.com>
Date: Tue, 24 Feb 2015 12:47:31 -0600
Message-ID: <CAK3OfOizMO84E3RAaBWVBNKg2qyM_XNhm2aG_mhy-scTLnVbhw@mail.gmail.com>
From: Nico Williams <nico@cryptonector.com>
To: Simo Sorce <simo@redhat.com>
Cc: "krbdev@mit.edu" <krbdev@mit.edu>
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: krbdev-bounces@mit.edu
There is work under way to add confidentiality protection to DNS
queries and responses, FYI.
Basically, to make this work you'll have to say that DNSSEC support
and use on the client side is required (zones can opt-out, as always).
And you may have to say something about MITMs and sname leakage.
You're right that the srealm is probably a lost cause in all cases.
_______________________________________________
krbdev mailing list krbdev@mit.edu
https://mailman.mit.edu/mailman/listinfo/krbdev