So, I'm still fairly uncomfortable - having a VPN provider able to override my DNSSEC configuration worries me, especially if things like TLSA / DNSSEC Chain Extension / similar are used. I was starting to come to terms with this, as I'd assumed that the common deployment scenario was "Install (as root / admin) this binary package containing a VPN client.", in which case a malicious VPN provider already has the ability to do, well, basically anything (and doesn't need this method to be malicious), but if this isn't the universal case, I'm concerned again...
A number of other IESG folk were also concerned - as a compromise, I'm going to ask DNSOP to have a look at the document (it is, after all, quite DNS related) and get their feedback. I am sympathetic to the general use case, but really don't want this to open scary security holes / decrease "trust" in DNSSEC. W On Wed, Nov 21, 2018 at 11:42 AM Paul Wouters <[email protected]> wrote: > On Nov 21, 2018, at 23:04, Warren Kumari <[email protected]> wrote: > > > Well, if you removed the DNSSEC_TA bit, and expected enterprise tools to > do this through "normal" enterprise tools methods this would work. > > > That is basically what we did with the mandatory white list, except now > the internal zones can still do rollovers without locking out all VPN > clients that haven’t recently done some (automatic or manual) provisioning > update that isn’t standardized. > > And in the end, if a user treats/trusts a generic VPN service provider the > same as an enterprise provisioning system, then we cannot define them to be > different. That is, whatever you define as out of band, non-ike enterprise > provisioning with be equally weak to this attack if provided by the generic > VPN provider. Kittens all the way down. > > Paul > > > > (It started writing that the zone could also be unsigned, but that > obviously doesn't work in the case of non-delegated "TLDs"...) > > W > > > >> But in the end, it all depends on >> how badly you want your VPN service to see cute kittens. >> >> Paul >> > > > -- > I don't think the execution is relevant when it was obviously a bad idea > in the first place. > This is like putting rabid weasels in your pants, and later expressing > regret at having chosen those particular rabid weasels and that pair of > pants. > ---maf > > -- I don't think the execution is relevant when it was obviously a bad idea in the first place. This is like putting rabid weasels in your pants, and later expressing regret at having chosen those particular rabid weasels and that pair of pants. ---maf
_______________________________________________ IPsec mailing list [email protected] https://www.ietf.org/mailman/listinfo/ipsec
