Re: [dns-privacy] Authenticating DoT nameservers for insecure delegations

2018-09-28 Thread manu tman
On Fri, Sep 28, 2018 at 9:09 AM Paul Hoffman wrote: > On 28 Sep 2018, at 8:32, manu tman wrote: > > > I have been thinking of a way to authenticate DoT servers for delegations > > that cannot be validated using DANE as describe in Stephane’s draft > >

Re: [dns-privacy] Authenticating DoT nameservers for insecure delegations

2018-09-28 Thread Paul Hoffman
On 28 Sep 2018, at 8:32, manu tman wrote: > I have been thinking of a way to authenticate DoT servers for delegations > that cannot be validated using DANE as describe in Stephane’s draft > https://tools.ietf.org/html/draft-bortzmeyer-dprive-resolver-to-auth-01 > > The idea is to leverage both

[dns-privacy] Authenticating DoT nameservers for insecure delegations

2018-09-28 Thread manu tman
Hi all, I have been thinking of a way to authenticate DoT servers for delegations that cannot be validated using DANE as describe in Stephane’s draft https://tools.ietf.org/html/draft-bortzmeyer-dprive-resolver-to-auth-01 The idea is to leverage both DNSSEC and SPKI to authenticate a zone but by