On 14 Dec 2016, at 3:34, Shane Kerr wrote:

IPsec seems desirable because somehow it seems better to be able to
layer on top of security at the lowest level possible? Layer 3 instead
of layer 4?

Although I guess the only extra information we would be exposing with
TLS or DTLS would be the port numbers, which seems minimally useful to
an attacker.

Exactly. Further, you have to negotiate in IPsec which ports and addresses within the "range of one target address" the client has access to, and that (you would think simple) negotiation has proven too difficult for some IPsec developers in the past.

2) Which authentication(s) to use?

I really like the CGA approach, but realistically I don't think that
would be accepted. If we think that it would be, then I'm all for it.

Why do you think it would not be accepted? It could be used where
available, and fall back to current authentication when it isn't.

CGA requires IPv6, and the hash is only 60-some bits long, so maybe it
is both too futuristic and not future-proofed at the same time. Like I
said, I really like it but I can see push-back.

Got it. I thought you meant "CGA-like DNS", not actual CGA. DNScurve's method of having he key in a DNS label is "CGA-like DNS" to me. I happen to like it a lot.

--Paul Hoffman

_______________________________________________
dns-privacy mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/dns-privacy

Reply via email to