BLU Discuss list archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[Discuss] free SSL certs from the EFF
- Subject: [Discuss] free SSL certs from the EFF
- From: richard.pieri at gmail.com (Richard Pieri)
- Date: Tue, 02 Dec 2014 14:14:59 -0500
- In-reply-to: <sjm8uiqc7sw.fsf@securerf.ihtfp.org>
- References: <546C4823.6060900@gmail.com> <BN3PR0401MB1204BAB10AE6249C54E4E81BDC760@BN3PR0401MB1204.namprd04.prod.outlook.com> <54737E7C.5040506@mattgillen.net> <BN3PR0401MB1204CDD16766109B0CD095ECDC730@BN3PR0401MB1204.namprd04.prod.outlook.com> <sjm8uirdxem.fsf@securerf.ihtfp.org> <BN3PR0401MB1204B299B351DFF7F2E85FBDDC7D0@BN3PR0401MB1204.namprd04.prod.outlook.com> <sjmlhmqcb1j.fsf@securerf.ihtfp.org> <BN3PR0401MB120492A5BDE4D3CEE0AECDD3DC7A0@BN3PR0401MB1204.namprd04.prod.outlook.com> <sjm8uiqc7sw.fsf@securerf.ihtfp.org>
Derek, According to the DNSSEC specs, if there is no RRSIG record in the lookup answer then a properly behaved resolver will treat it as unsigned. Backwards compatibility with so-called insecure DNS is an explicit requirement of DNSSEC. So, what happens when a malicious actor inserts filters at an intermediary resolver or router that strip RRSIG records from DNS answers? DNSSEC was never intended to protect you against that. It was designed to protect high-level caches -- root zones, ISP's, big data players, private networks, and the like -- from cache poisoning. That's it. Any benefits that might trickle down to you are incidental. Never mind that DNSSEC has no means of rolling over the root KSKs. If a root is compromised then the whole domain hierarchy is compromised and there currently is no way to fix that other than disabling DNSSEC for the hierarchy or accepting loss of service for everything under that root. Aside: It's DNSSEC. It is not DNSsec, nor DNS-SEC, nor dns-sec, nor DNS-sec, nor is it any variant that is not DNSSEC. -- Rich P.
- Follow-Ups:
- [Discuss] free SSL certs from the EFF
- From: warlord at MIT.EDU (Derek Atkins)
- [Discuss] free SSL certs from the EFF
- References:
- [Discuss] free SSL certs from the EFF
- From: warlord at MIT.EDU (Derek Atkins)
- [Discuss] free SSL certs from the EFF
- From: blu at nedharvey.com (Edward Ned Harvey (blu))
- [Discuss] free SSL certs from the EFF
- From: warlord at MIT.EDU (Derek Atkins)
- [Discuss] free SSL certs from the EFF
- From: blu at nedharvey.com (Edward Ned Harvey (blu))
- [Discuss] free SSL certs from the EFF
- From: warlord at MIT.EDU (Derek Atkins)
- [Discuss] free SSL certs from the EFF
- Prev by Date: [Discuss] is it hard to install linux/ubuntu for dual boot on windows 7 ultimate?
- Next by Date: [Discuss] Python module for Windows services that runs on Linux
- Previous by thread: [Discuss] free SSL certs from the EFF
- Next by thread: [Discuss] free SSL certs from the EFF
- Index(es):