[19122] in Kerberos_V5_Development
Re: Proposal for using NAPTR/URI records
daemon@ATHENA.MIT.EDU (Nico Williams)
Thu Feb 26 14:20:24 2015
Date: Thu, 26 Feb 2015 13:20:07 -0600
From: Nico Williams <nico@cryptonector.com>
To: Petr Spacek <pspacek@redhat.com>
Message-ID: <20150226192006.GF9895@localhost>
MIME-Version: 1.0
Content-Disposition: inline
In-Reply-To: <54EF5193.8040808@redhat.com>
Cc: krbdev@mit.edu
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: krbdev-bounces@mit.edu
On Thu, Feb 26, 2015 at 06:02:11PM +0100, Petr Spacek wrote:
> I forgot to comment on this:
> QTYPE=ANY is unreliable because admins are disabling it in hope that
> it will mitigate DNS-amplified DDoS attacks. (It would be better to
> implement source-address filtering but what you can do ...)
I see, and it's probably a good idea, but in a DNSSEC world this is
equivalent to timing out, no?
> Unfortunately I do not have any data at hand but I believe that Viktor
> Dukhovni or other folks interested in DNS and mail server could add
> some details.
I'll ask him.
> Maybe this whole discussion should be moved to IETF dnsop mailing
> list? After all, there is nothing Kerberos-specific, all the questions
> seems to be about DNS service discovery.
Well, but there is something for KITTEN WG as well, since there'd be new
requirements for KDC operators and -likely, or at least recommendations-
for client implementors.
I agree that dnsop is probably the better venue. It's definitely
getting to the point where we should go ask for expert DNS advice, and
NOTE WELL.
Nico
--
_______________________________________________
krbdev mailing list krbdev@mit.edu
https://mailman.mit.edu/mailman/listinfo/krbdev