BLU Discuss list archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[Discuss] free SSL certs from the EFF
- Subject: [Discuss] free SSL certs from the EFF
- From: richard.pieri at gmail.com (Richard Pieri)
- Date: Mon, 01 Dec 2014 18:22:34 -0500
- In-reply-to: <sjm8uirdxem.fsf@securerf.ihtfp.org>
- References: <546C4823.6060900@gmail.com> <BN3PR0401MB1204BAB10AE6249C54E4E81BDC760@BN3PR0401MB1204.namprd04.prod.outlook.com> <54737E7C.5040506@mattgillen.net> <BN3PR0401MB1204CDD16766109B0CD095ECDC730@BN3PR0401MB1204.namprd04.prod.outlook.com> <sjm8uirdxem.fsf@securerf.ihtfp.org>
On 12/1/2014 1:42 PM, Derek Atkins wrote: > I think it depends very much on your definition of "Secure". You are > correct that DNSsec does not provide any confidentiality services. > However it does indeed protect the data integrity from interloping > intermediaries and provide authenticated DNS Data. No, it doesn't. It only prevents cache poisoning when DNSSEC is enforced on your resolvers. If you do not enforce DNSSEC on your resolvers then your resolvers will accept any unsigned RRs including those that have had the RRSIG records stripped by malicious intermediaries. -- Rich P.
- Follow-Ups:
- [Discuss] free SSL certs from the EFF
- From: warlord at MIT.EDU (Derek Atkins)
- [Discuss] free SSL certs from the EFF
- From: bogstad at pobox.com (Bill Bogstad)
- [Discuss] free SSL certs from the EFF
- References:
- [Discuss] free SSL certs from the EFF
- From: warlord at MIT.EDU (Derek Atkins)
- [Discuss] free SSL certs from the EFF
- Prev by Date: [Discuss] Ixsystems nas storage?
- Next by Date: [Discuss] free SSL certs from the EFF
- Previous by thread: [Discuss] free SSL certs from the EFF
- Next by thread: [Discuss] free SSL certs from the EFF
- Index(es):