Re: [DNSOP] I-D Action: draft-pwouters-powerbind-04.txt

2020-05-11 Thread Vladimír Čunát
On 5/7/20 6:06 AM, Paul Wouters wrote: > On Tue, 5 May 2020, Vladimír Čunát wrote: >> 1. Validation without logging. >> At the end of 3.1 you claim that mode is still useful.  When I focus on >> intentional attacks, signing a malicious DS seems among the easiest >> ones, and that can't be detected

Re: [DNSOP] I-D Action: draft-pwouters-powerbind-04.txt

2020-05-06 Thread Paul Wouters
On Tue, 5 May 2020, Vladimír Čunát wrote: 1. Validation without logging. At the end of 3.1 you claim that mode is still useful.  When I focus on intentional attacks, signing a malicious DS seems among the easiest ones, and that can't be detected without the attacked machine doing logging (the

Re: [DNSOP] I-D Action: draft-pwouters-powerbind-04.txt

2020-05-05 Thread Vladimír Čunát
Hello, I'm still a bit skeptical. 1. Validation without logging. At the end of 3.1 you claim that mode is still useful.  When I focus on intentional attacks, signing a malicious DS seems among the easiest ones, and that can't be detected without the attacked machine doing logging (the DS might be

Re: [DNSOP] I-D Action: draft-pwouters-powerbind-04.txt

2020-04-30 Thread Wes Hardaker
internet-dra...@ietf.org writes: > A New Internet-Draft is available from the on-line Internet-Drafts > directories. > This draft is a work item of the Domain Name System Operations WG of > the IETF. Per discussion in the adoption thread, this primarily updates sections 1 and 3 with a stronger

[DNSOP] I-D Action: draft-pwouters-powerbind-04.txt

2020-04-30 Thread internet-drafts
A New Internet-Draft is available from the on-line Internet-Drafts directories. This draft is a work item of the Domain Name System Operations WG of the IETF. Title : The DELEGATION_ONLY DNSKEY flag Authors : Paul Wouters Wes Hardaker