Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
dotwaffle
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
61.
▲
by
dotwaffle
3y ago
At first glance I thought this was going to be a reinvented Sun Ray!
62.
▲
by
dotwaffle
4y ago
SSHFP records largely solves the host key problem, but yes, the user is the weak point in the chain there.
63.
▲
by
dotwaffle
4y ago
Hesiod uses txt records. I am using IN class records too, as I do not have a DNS provider that supports HS class... But that's fine, it works!
64.
▲
by
dotwaffle
4y ago
And I may well do. But it's probably not the best idea to do this on a larger scale, there are valid reasons why this is not a good thing to recommend -- if you miss one part (DNSSEC signing, or running a local validating resolver) you
65.
▲
by
dotwaffle
4y ago
A blog on this.
66.
▲
by
dotwaffle
4y ago
My TTL is lower than most people's SSH certificate validity duration, for sure :)
67.
▲
by
dotwaffle
4y ago
Good luck with that. DNS TXT records are used for a lot of infrastructure right now, from DMARC/SPF/DKIM to DNS-01 validation through LetsEncrypt afaik.
68.
▲
by
dotwaffle
4y ago
It would be rude of me to decline such an offer ;)
69.
▲
by
dotwaffle
4y ago
My DNS zones are not hosted on those servers, Google Cloud DNS does the dnssec signing, and there is a breakglass key installed on there too that when used automatically sends alerts out.
70.
▲
by
dotwaffle
4y ago
You'd have to compromise not only the root keys just to get into my infrastructure, but sign all the zones from there downwards, and intercept all DNS traffic leaving that server in the first place. That's secure enough for me.
71.
▲
by
dotwaffle
4y ago
I store my authorized_keys in DNS TXT records, that are DNSSEC signed, with a validating resolver on the box. I then just use "/usr/bin/hesinfo %u ssh" as my AuthorizedKeysCommand in OpenSSH. I wrote a little tool t