Greetings again. I was surprised, but happy, to not see a requirement in the 
list for authentication of servers in the list. However, I suspect that this 
might have been an oversight, and the endless debate on authentication 
requirements will start as soon as there is a proposed protocol document.

My preference would be that the core requirement is that ADoT servers use 
either IP address or DNS name authentication in their certificates, but that 
the certificates can be issued by any CA, including being self-issued. The core 
requirement could also go on to say that resolvers be able to authenticate 
servers for logging purposes, but not be required to break TLS connections if 
the server's identity cannot be authenticated against the resolver's set of 
trust anchors.

--Paul Hoffman
_______________________________________________
dns-privacy mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/dns-privacy

Reply via email to