Alerts This Week
Warning Icon 1 666
Alerts This Week
Warning Icon 1 666

Stay Ahead With Linux Security News

Filter Icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found -4 articles for you...
67

FreeS/WAN: DNS Key-Restrict Draft Threatens Public Key Distribution

This week's lists.freeswan.org Email Summary reports that Michael Richardson debated the new DNS Key-Restrict draft with folks from the list This email address is being protected from spambots. You need JavaScript enabled to view it.. If that draft is widely implemented, FreeS/WAN will need to use a different DNS record type to distribute public keys. Interesting stuff.. . .. This week's lists.freeswan.org Email Summary reports that Michael Richardson debated the new DNS Key-Restrict draft with folks from the list This email address is being protected from spambots. You need JavaScript enabled to view it.. If that draft is widely implemented, FreeS/WAN will need to use a different DNS record type to distribute public keys. Interesting stuff. The DNS (Domain Name Service) Working Group of the IETF (International Engineering Task Force) has decided to restrict the use of KEY records to DNSsec keys, and has published its intent in a Key-Restrict draft. This draft is an attempt to solve the "sub-typing problem": once you have more than one type of KEY, for DNSsec and other purposes, how do you differentiate between these types? Since Opportunistic Encryption (OE) is designed to rely on the KEY record to distribute IPsec public keys, the Working Group's decision affects the Linux FreeS/WAN project. Michael Richardson, Linux FreeS/WAN programmer, opposes the measures outlined in the draft. He commented, "[a]ny proposal that removes functionality without offering an immediate alternative is a complete and total non-starter." Notably, the draft does not suggest an alternative to the KEY record for other interests (for example IPsec and SSH) who are using, or would like to use, the KEY RR to distribute other information essential to network communications. Scott Rose remarked on the proposed solution: Restricting KEY to DNSSEC only does solve the sub-typing problem - for DNSSEC. For everything else that wishes to use the DNS to store keys (IPSec and SSH are the only 2 that come to mind). APPKEY faced the same problem - it just pushed the subtyping problem off to all the other protocols and left DNSSEC as thelucky one. He proposed an analogous effort for other key types: If it is good to restrict KEY to DNSSEC, then having a separate RR type for any other public key is a good idea too. In keeping with this idea, Derek Atkins suggested Michael Richardson "write a draft that defines a new FSKEY record that defines how to store FreeS/WAN keys in DNS". Derek added: My recollection of reading the OE draft was that you needed additional information above and beyond what was provided by the KEY record. In particular, IIRC, you needed a pointer to the gateway and the network size to use. This would be the perfect opportunity to combine this all into a single record! According to Scott, the whole process might benefit from a longer view. He recommended: a BOF [in Atlanta] about using DNS to support other applications and set up a general framework/process for getting any type of network information in the DNS. Not just keys. Michael commented that the problem needed to be solved soon: For another month or so, I can change how Opportunistic Encryption works. It will be painful, but we can do it. If the change is not proposed now, then we will continue deploying with the status quo, which is well supported. He insisted that the solution ought to be created by the folks who would restrict the use of the KEY record that FreeS/WAN now uses. More detail on the whole debate may be found in the thread. The link for this article located at FreeS/WAN Project is no longer available. . This week's lists.freeswan.org Email Summary reports that Michael Richardson debated the new DNS Key. week's, lists, freeswan, email, summary, reports, michael, richardson, debated. . LinuxSecurity.com Team

Calendar 2 Aug 07, 2002 User Avatar LinuxSecurity.com Team Cryptography
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here