[19099] in Kerberos_V5_Development
Re: Proposal for using NAPTR/URI records
daemon@ATHENA.MIT.EDU (Simo Sorce)
Tue Feb 24 14:22:21 2015
Message-ID: <1424805724.13431.25.camel@willson.usersys.redhat.com>
From: Simo Sorce <simo@redhat.com>
To: Nico Williams <nico@cryptonector.com>
Date: Tue, 24 Feb 2015 14:22:04 -0500
In-Reply-To: <CAK3OfOizMO84E3RAaBWVBNKg2qyM_XNhm2aG_mhy-scTLnVbhw@mail.gmail.com>
Mime-Version: 1.0
Cc: "krbdev@mit.edu" <krbdev@mit.edu>
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: krbdev-bounces@mit.edu
On Tue, 2015-02-24 at 12:47 -0600, Nico Williams wrote:
> There is work under way to add confidentiality protection to DNS
> queries and responses, FYI.
>
> Basically, to make this work you'll have to say that DNSSEC support
> and use on the client side is required (zones can opt-out, as always).
> And you may have to say something about MITMs and sname leakage.
> You're right that the srealm is probably a lost cause in all cases.
Sorry, but if you are using DNSSEC, MITM is not a problem, so
unfortunately I do not understand your concerns with more info on the
assumptions you are making.
Simo.
--
Simo Sorce * Red Hat, Inc * New York
_______________________________________________
krbdev mailing list krbdev@mit.edu
https://mailman.mit.edu/mailman/listinfo/krbdev