5 ms·
What do you mean?
by StuntPope 11y ago
What do you mean?
- yuhong 11y agoDNSSEC has several problems some of which is in the design, as tptacek likes to mention.
- StuntPope 11y agoBut what do you mean by "online signing" ?
- yuhong 11y agoOne of the problems is that it exposed DNS zone information, and one of the reason it did that was it was designed to require signing only once and after that the private key didn't have to be used again until the zone info changes.
- indolering 11y agoAre you talking about zone enumeration? That's covered in the article.
- geofft 11y agoCan you provide an NSEC white-lie response to an arbitrary query without an online key? (I'm not sure if this is what was being asked, but I'm curious about the answer to that, either way.)
- yuhong 11y agoDon't think so.
- indolering 11y agoI believe so: http://dankaminsky.com/2011/01/05/djb-ccc/#whitelies http://dankaminsky.com/2011/01/05/djb-ccc/#whitelies (Phreebird is an online signer, but I don't see why an offline signer couldn't generate these proofs.)
- tptacek 11y agoBecause you can't predict offline which names you need to obscure with fake NSEC records. If there is any company in the world actually using Phreebird in production, I'd --- for more than one reason --- like to know about it.
- Habbie 11y agoI don't know of any either, but there are plenty running PowerDNS in online 'white lies' signing mode. And then, of course, there is Cloudflare. (And indeed, it cannot be done offline - although doing much narrower NSEC/NSEC3 ranges than 'normal' could be done offline).
- Habbie 11y agoNo, not in the narrowest way. You can go 'somewhere in between' at the cost of blowing up your zone size tremendously, but it's not worth it.
- deleted 11y ago[deleted]
- indolering 11y agoThis post directly addresses each point that Ptacek raised in his "Against DNSSEC" blogpost and FAQ.
- feld 11y agoPoorly and unconvincingly addresses. Same argument we've seen over and over -- now in a nice clean FAQ! Doesn't change the design problems. Just tries to hide them behind half-truths and "but there's nothing better..."
- indolering 11y agoSigning DNS records using a machine connected to the internet, instead of passing the zone files to an air-gapped signing machine over a sneakernet. Eventually, you run into the issue of updating the "offline" machine and many places just have an "online" machine that gets the zone files through a highly restricted interface.
- realityking 11y agoWe're currently working on providing DNSSEC for our customers. The problem with only signing is that we really don't want all the keys to be physically present on our DNS servers, as many of them are hosted in other companies data centres. Having a central online signing server is bad for availability, as DNS down time is really not acceptable. That basically only leaves offline signing.