On Nov 21, 2018, at 23:04, Warren Kumari <[email protected]> wrote:
> 
>> 
> 
> Well, if you removed the DNSSEC_TA bit, and expected enterprise tools to do 
> this through "normal" enterprise tools methods this would work.

That is basically what we did with the mandatory white list, except now the 
internal zones can still do rollovers without locking out all VPN clients that 
haven’t recently done some (automatic or manual) provisioning update that isn’t 
standardized.

And in the end, if a user treats/trusts a generic VPN service provider the same 
as an enterprise provisioning system, then we cannot define them to be 
different. That is, whatever you define as out of band, non-ike enterprise 
provisioning with be equally weak to this attack if provided by the generic VPN 
provider. Kittens all the way down.

Paul



> (It started writing that the zone could also be unsigned, but that obviously 
> doesn't work in the case of non-delegated "TLDs"...)
> 
> W
> 
>  
>> But in the end, it all depends on
>> how badly you want your VPN service to see cute kittens.
>> 
>> Paul
> 
> 
> -- 
> I don't think the execution is relevant when it was obviously a bad idea in 
> the first place.
> This is like putting rabid weasels in your pants, and later expressing regret 
> at having chosen those particular rabid weasels and that pair of pants.
>    ---maf
_______________________________________________
IPsec mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/ipsec

Reply via email to