[19102] in Kerberos_V5_Development

home help back first fref pref prev next nref lref last post

Re: Proposal for using NAPTR/URI records

daemon@ATHENA.MIT.EDU (Simo Sorce)
Tue Feb 24 14:57:06 2015

Message-ID: <1424807731.13431.30.camel@willson.usersys.redhat.com>
From: Simo Sorce <simo@redhat.com>
To: Nico Williams <nico@cryptonector.com>
Date: Tue, 24 Feb 2015 14:55:31 -0500
In-Reply-To: <CAK3OfOhBb0=+OneLoa-pcaMMZtZYvLD0ZdkmYuoURJXTn0_qxg@mail.gmail.com>
Mime-Version: 1.0
Cc: "krbdev@mit.edu" <krbdev@mit.edu>
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: krbdev-bounces@mit.edu

On Tue, 2015-02-24 at 13:42 -0600, Nico Williams wrote:
> On Tue, Feb 24, 2015 at 1:22 PM, Simo Sorce <simo@redhat.com> wrote:
> > Sorry, but if you are using DNSSEC, MITM is not a problem, so
> > unfortunately I do not understand your concerns with more info on the
> > assumptions you are making.
> 
> The proposal did not mention DNSSEC.  I'm saying you'll need to say
> something about at least that.

You are still not saying why.
The NAPTR proposal does not seem to add any attack vector that is not
already present with the current DNS SRV record discovery mechanism that
is supported in MIT Kerberos and other implementations.
So I see nothing new that needs highlighting.

Simo.

-- 
Simo Sorce * Red Hat, Inc * New York

_______________________________________________
krbdev mailing list             krbdev@mit.edu
https://mailman.mit.edu/mailman/listinfo/krbdev

home help back first fref pref prev next nref lref last post