[19102] in Kerberos_V5_Development
Re: Proposal for using NAPTR/URI records
daemon@ATHENA.MIT.EDU (Simo Sorce)
Tue Feb 24 14:57:06 2015
Message-ID: <1424807731.13431.30.camel@willson.usersys.redhat.com>
From: Simo Sorce <simo@redhat.com>
To: Nico Williams <nico@cryptonector.com>
Date: Tue, 24 Feb 2015 14:55:31 -0500
In-Reply-To: <CAK3OfOhBb0=+OneLoa-pcaMMZtZYvLD0ZdkmYuoURJXTn0_qxg@mail.gmail.com>
Mime-Version: 1.0
Cc: "krbdev@mit.edu" <krbdev@mit.edu>
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: krbdev-bounces@mit.edu
On Tue, 2015-02-24 at 13:42 -0600, Nico Williams wrote:
> On Tue, Feb 24, 2015 at 1:22 PM, Simo Sorce <simo@redhat.com> wrote:
> > Sorry, but if you are using DNSSEC, MITM is not a problem, so
> > unfortunately I do not understand your concerns with more info on the
> > assumptions you are making.
>
> The proposal did not mention DNSSEC. I'm saying you'll need to say
> something about at least that.
You are still not saying why.
The NAPTR proposal does not seem to add any attack vector that is not
already present with the current DNS SRV record discovery mechanism that
is supported in MIT Kerberos and other implementations.
So I see nothing new that needs highlighting.
Simo.
--
Simo Sorce * Red Hat, Inc * New York
_______________________________________________
krbdev mailing list krbdev@mit.edu
https://mailman.mit.edu/mailman/listinfo/krbdev