On 14 Dec 2016, at 3:34, Shane Kerr wrote:
IPsec seems desirable because somehow it seems better to be able to
layer on top of security at the lowest level possible? Layer 3 instead
of layer 4?
Although I guess the only extra information we would be exposing with
TLS or DTLS would be the port numbers, which seems minimally useful to
an attacker.
Exactly. Further, you have to negotiate in IPsec which ports and
addresses within the "range of one target address" the client has access
to, and that (you would think simple) negotiation has proven too
difficult for some IPsec developers in the past.
2) Which authentication(s) to use?
I really like the CGA approach, but realistically I don't think that
would be accepted. If we think that it would be, then I'm all for
it.
Why do you think it would not be accepted? It could be used where
available, and fall back to current authentication when it isn't.
CGA requires IPv6, and the hash is only 60-some bits long, so maybe it
is both too futuristic and not future-proofed at the same time. Like I
said, I really like it but I can see push-back.
Got it. I thought you meant "CGA-like DNS", not actual CGA. DNScurve's
method of having he key in a DNS label is "CGA-like DNS" to me. I happen
to like it a lot.
--Paul Hoffman
_______________________________________________
dns-privacy mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/dns-privacy