BLU Discuss list archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[Discuss] free SSL certs from the EFF
- Subject: [Discuss] free SSL certs from the EFF
- From: warlord at MIT.EDU (Derek Atkins)
- Date: Tue, 02 Dec 2014 10:46:24 -0500
- In-reply-to: <547CF83A.8030205@gmail.com> (Richard Pieri's message of "Mon, 01 Dec 2014 18:22:34 -0500")
- References: <546C4823.6060900@gmail.com> <BN3PR0401MB1204BAB10AE6249C54E4E81BDC760@BN3PR0401MB1204.namprd04.prod.outlook.com> <54737E7C.5040506@mattgillen.net> <BN3PR0401MB1204CDD16766109B0CD095ECDC730@BN3PR0401MB1204.namprd04.prod.outlook.com> <sjm8uirdxem.fsf@securerf.ihtfp.org> <547CF83A.8030205@gmail.com>
Richard Pieri <richard.pieri at gmail.com> writes: > On 12/1/2014 1:42 PM, Derek Atkins wrote: >> I think it depends very much on your definition of "Secure". You are >> correct that DNSsec does not provide any confidentiality services. >> However it does indeed protect the data integrity from interloping >> intermediaries and provide authenticated DNS Data. > > No, it doesn't. It only prevents cache poisoning when DNSSEC is > enforced on your resolvers. If you do not enforce DNSSEC on your > resolvers then your resolvers will accept any unsigned RRs including > those that have had the RRSIG records stripped by malicious > intermediaries. Well, duh.. And if you don't check the validity of your TLS certs then you can be MITM'ed too. Of course DNSsec requires a DNSsec-aware resolver; it cannot protect someone who doesn't want to be protected. You can put a lock on your front door but it doesn't do any good if you don't actually lock it!! But you're looking at the wrong issue; DNSsec-capable resolvers exist and have existed for years. In fact I would bet your current Linux host has a DNSsec-capable resolver. It might not be turned on by default, but they are definitely out there. -derek -- Derek Atkins, SB '93 MIT EE, SM '95 MIT Media Laboratory Member, MIT Student Information Processing Board (SIPB) URL: http://web.mit.edu/warlord/ PP-ASEL-IA N1NWH warlord at MIT.EDU PGP key available
- References:
- [Discuss] free SSL certs from the EFF
- From: warlord at MIT.EDU (Derek Atkins)
- [Discuss] free SSL certs from the EFF
- From: richard.pieri at gmail.com (Richard Pieri)
- [Discuss] free SSL certs from the EFF
- Prev by Date: [Discuss] free SSL certs from the EFF
- Next by Date: [Discuss] Python module for Windows services that runs on Linux
- Previous by thread: [Discuss] free SSL certs from the EFF
- Next by thread: [Discuss] Python module for Windows services that runs on Linux
- Index(es):