Paul,

At 2016-12-13 11:24:29 -0500
Paul Wouters <[email protected]> wrote:

> >> AIUI the draft, if we want to use DNS the problem is that we want to
> >> know how to encrypt a session to a name server, but we can't look up
> >> anything about the name server in the DNS because we don't yet know
> >> how to encrypt a session to the name server.  
> >
> > I disagree. We can look up without keys. It just has to be without
> > privacy.  
> 
> Even better, since you are going to setup a secure connection to that name
> server anyway, there is no privacy lost by querying for its public key
> in DNS out in the open.

That assumes that the server will be publishing its own information. I
don't think that this is necessarily true - although perhaps it can be
made a requirement (or recommendation) for encrypted communication?

But yes this is actually a fairly compelling observation. :)

Cheers,

--
Shane

Attachment: pgp0vUAB2QWdW.pgp
Description: OpenPGP digital signature

_______________________________________________
dns-privacy mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/dns-privacy

Reply via email to