Paul,

At 2016-12-14 07:24:44 -0800
"Paul Hoffman" <[email protected]> wrote:
> 
> >>>> 2) Which authentication(s) to use?  
> >>>
> >>> I really like the CGA approach, but realistically I don't think that
> >>> would be accepted. If we think that it would be, then I'm all for 
> >>> it.  
> >>
> >> Why do you think it would not be accepted? It could be used where
> >> available, and fall back to current authentication when it isn't.  
> >
> > CGA requires IPv6, and the hash is only 60-some bits long, so maybe it
> > is both too futuristic and not future-proofed at the same time. Like I
> > said, I really like it but I can see push-back.  
> 
> Got it. I thought you meant "CGA-like DNS", not actual CGA. DNScurve's 
> method of having he key in a DNS label is "CGA-like DNS" to me. I happen 
> to like it a lot.

I agree, publishing the key in the DNS label is actually quite a clever
hack. But does this count as "novel security"? :)

To be honest, I don't see any major drawbacks to something like this
approach.

We could perhaps use something like "xn--" to identify names which
contain keys (I propose "djb--", although maybe we should ask Mr.
Bernstein before adopting that). That leaves 58 characters in a label,
which is enough for around 300 bits if encoded in base 36 (alphanumeric
only) - that seems enough for a fingerprint right? And multiple labels
are possible if needed.

Cheers,

--
Shane

Attachment: pgprr8levbqmb.pgp
Description: OpenPGP digital signature

_______________________________________________
dns-privacy mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/dns-privacy

Reply via email to