Paul, At 2016-12-14 07:24:44 -0800 "Paul Hoffman" <[email protected]> wrote: > > >>>> 2) Which authentication(s) to use? > >>> > >>> I really like the CGA approach, but realistically I don't think that > >>> would be accepted. If we think that it would be, then I'm all for > >>> it. > >> > >> Why do you think it would not be accepted? It could be used where > >> available, and fall back to current authentication when it isn't. > > > > CGA requires IPv6, and the hash is only 60-some bits long, so maybe it > > is both too futuristic and not future-proofed at the same time. Like I > > said, I really like it but I can see push-back. > > Got it. I thought you meant "CGA-like DNS", not actual CGA. DNScurve's > method of having he key in a DNS label is "CGA-like DNS" to me. I happen > to like it a lot.
I agree, publishing the key in the DNS label is actually quite a clever hack. But does this count as "novel security"? :) To be honest, I don't see any major drawbacks to something like this approach. We could perhaps use something like "xn--" to identify names which contain keys (I propose "djb--", although maybe we should ask Mr. Bernstein before adopting that). That leaves 58 characters in a label, which is enough for around 300 bits if encoded in base 36 (alphanumeric only) - that seems enough for a fingerprint right? And multiple labels are possible if needed. Cheers, -- Shane
pgprr8levbqmb.pgp
Description: OpenPGP digital signature
_______________________________________________ dns-privacy mailing list [email protected] https://www.ietf.org/mailman/listinfo/dns-privacy
