BLU Discuss list archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[Discuss] free SSL certs from the EFF
- Subject: [Discuss] free SSL certs from the EFF
- From: blu at nedharvey.com (Edward Ned Harvey (blu))
- Date: Tue, 2 Dec 2014 14:35:53 +0000
- In-reply-to: <CAJFsZ=qy89Rp9CjQEV9GNL7hXuTJgqaFSdzgv4V70ENXtuXw8g@mail.gmail.com>
- References: <546C4823.6060900@gmail.com> <BN3PR0401MB1204BAB10AE6249C54E4E81BDC760@BN3PR0401MB1204.namprd04.prod.outlook.com> <54737E7C.5040506@mattgillen.net> <BN3PR0401MB1204CDD16766109B0CD095ECDC730@BN3PR0401MB1204.namprd04.prod.outlook.com> <sjm8uirdxem.fsf@securerf.ihtfp.org> <547CF83A.8030205@gmail.com> <CAJFsZ=qy89Rp9CjQEV9GNL7hXuTJgqaFSdzgv4V70ENXtuXw8g@mail.gmail.com>
> From: discuss-bounces+blu=nedharvey.com at blu.org [mailto:discuss- > bounces+blu=nedharvey.com at blu.org] On Behalf Of Bill Bogstad > > As far as I can tell, the problem with DNSSEC isn't with the > underlying protocols/processes; it is the chicken and egg deployment > problem. As Ed Harvey discusses in a different message, not all > zones are signed. This causes lots of problems. There are lots of possible ways to solve the problem. A really obvious one would be to create a "secure" DNS service, which is functionally equivalent to regular DNS, except that all query responses must be signed, and that includes signing the "NX_DOMAIN" response, which would then give the client the ability to verifiably determine whether or not a secure response should have existed for a particular query. That is, unless a malicious DNS root server provides maliciously crafted responses. Another way would be to mandate that all DNS must be secure by some deadline. By brute force and legal intervention, forcibly obsolete insecure DNS. Another solution would be to simply require all non-DNS communications use SSL/TLS. For example, you don't have to worry about hacked up DNS, if you're using https://blahblah. Because if the DNS response is invalid, your https protocol is going to detect an invalid server cert. And there are some other possibilities as well.
- References:
- [Discuss] free SSL certs from the EFF
- From: warlord at MIT.EDU (Derek Atkins)
- [Discuss] free SSL certs from the EFF
- From: richard.pieri at gmail.com (Richard Pieri)
- [Discuss] free SSL certs from the EFF
- From: bogstad at pobox.com (Bill Bogstad)
- [Discuss] free SSL certs from the EFF
- Prev by Date: [Discuss] is it hard to install linux/ubuntu for dual boot on windows 7 ultimate?
- Next by Date: [Discuss] free SSL certs from the EFF
- Previous by thread: [Discuss] free SSL certs from the EFF
- Next by thread: [Discuss] free SSL certs from the EFF
- Index(es):