[19097] in Kerberos_V5_Development

home help back first fref pref prev next nref lref last post

Re: Proposal for using NAPTR/URI records

daemon@ATHENA.MIT.EDU (Nico Williams)
Tue Feb 24 13:47:42 2015

MIME-Version: 1.0
In-Reply-To: <1424800004.13431.19.camel@willson.usersys.redhat.com>
Date: Tue, 24 Feb 2015 12:47:31 -0600
Message-ID: <CAK3OfOizMO84E3RAaBWVBNKg2qyM_XNhm2aG_mhy-scTLnVbhw@mail.gmail.com>
From: Nico Williams <nico@cryptonector.com>
To: Simo Sorce <simo@redhat.com>
Cc: "krbdev@mit.edu" <krbdev@mit.edu>
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: krbdev-bounces@mit.edu

There is work under way to add confidentiality protection to DNS
queries and responses, FYI.

Basically, to make this work you'll have to say that DNSSEC support
and use on the client side is required (zones can opt-out, as always).
And you may have to say something about MITMs and sname leakage.
You're right that the srealm is probably a lost cause in all cases.
_______________________________________________
krbdev mailing list             krbdev@mit.edu
https://mailman.mit.edu/mailman/listinfo/krbdev

home help back first fref pref prev next nref lref last post