Re: [IPsec] [dane] Bootstrapping IPSec from DNSSSEC/DANE

2013-09-21 Thread Paul Wouters
On Sat, 21 Sep 2013, Yoav Nir wrote: I believe this would require a separate document. But I'm not sure that tying it to an IP address is appropriate. IKE implementations work from behind NAT devices and sometimes move around (see MOBIKE), so I think it would be more appropriate to tie the re

Re: [IPsec] [dane] Bootstrapping IPSec from DNSSSEC/DANE

2013-09-21 Thread James Cloos
> I am interested in using a variant of DANE to bootstrap my IPSec IKE > root certificate trust. Is anyone aware of any work been done in this Start with rfcs 4025 and 4322. -JimC -- James Cloos OpenPGP: 1024D/ED7DAEA6 ___ IPsec mailing list

Re: [IPsec] [dane] Bootstrapping IPSec from DNSSSEC/DANE

2013-09-21 Thread Yoav Nir
Hi David I believe this would require a separate document. But I'm not sure that tying it to an IP address is appropriate. IKE implementations work from behind NAT devices and sometimes move around (see MOBIKE), so I think it would be more appropriate to tie the record to any type of ID payload

[IPsec] Bootstrapping IPSec from DNSSSEC/DANE

2013-09-21 Thread david . lloyd
Hi, I am interested in using a variant of DANE to bootstrap my IPSec IKE root certificate trust. Is anyone aware of any work been done in this area? >From my understanding, it looks as though the is no technical issue with using >reverse DNS lookup for the IPSec target machine with DNSSec (alt