On Wed, Dec 14, 2016 at 12:18:17PM +0100,
 Shane Kerr <[email protected]> wrote 
 a message of 87 lines which said:

> So basically you are advocating a model where meta-data
> (specifically lookups of NS records and their associated A/AAAA
> records) is public and other data is private?

Not at all. I'm suggesting (see the algorithm in
<https://tools.ietf.org/html/draft-bortzmeyer-dprive-step-2-04#section-3.2>
to switch to opportunistic mode (encrypt but do not try to
authenticate) when retrieving the DANE material. As soon as you get
enough information to authenticate, you go back to strict mode.

This is similar to what is suggested in
<https://tools.ietf.org/html/draft-ietf-dprive-dtls-and-tls-profiles-07#section-8.2.1>

_______________________________________________
dns-privacy mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/dns-privacy

Reply via email to