Paul, At 2016-12-13 11:24:29 -0500 Paul Wouters <[email protected]> wrote:
> >> AIUI the draft, if we want to use DNS the problem is that we want to > >> know how to encrypt a session to a name server, but we can't look up > >> anything about the name server in the DNS because we don't yet know > >> how to encrypt a session to the name server. > > > > I disagree. We can look up without keys. It just has to be without > > privacy. > > Even better, since you are going to setup a secure connection to that name > server anyway, there is no privacy lost by querying for its public key > in DNS out in the open. That assumes that the server will be publishing its own information. I don't think that this is necessarily true - although perhaps it can be made a requirement (or recommendation) for encrypted communication? But yes this is actually a fairly compelling observation. :) Cheers, -- Shane
pgp0vUAB2QWdW.pgp
Description: OpenPGP digital signature
_______________________________________________ dns-privacy mailing list [email protected] https://www.ietf.org/mailman/listinfo/dns-privacy
