[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: DNSEXT WGLC: IPv6 Name Auto Registration



-----BEGIN PGP SIGNED MESSAGE-----


>>>>> "Robert" == Robert Elz <kre@munnari.OZ.AU> writes:
    Robert> For v4 things aren't quite as bad, as DHCP servers update the DNS
    Robert> only with addresses the DHCP server has assigned, so there is at
    Robert> least some general reason for believing the DHCP server there.
    Robert> But for v6, DHCP servers will almost never be actually assigning
    Robert> addresses, so the server is just believing the client, and then
    Robert> taking that (unsubstantiated) data and sending it to the DNS
    Robert> server.  That doesn't sound good.

  No, it does not. But, that's not how I would do it.
  
    Robert> The experiment proposed in this draft also has an entity (the
    Robert> registrar) that can form a trust relationship with the DNS
    Robert> server, and but it doesn't get its data from what some random
    Robert> client tells it, but from what another (trusted) agent (the
    Robert> detector) tells it from what it observes of the network.

    Robert> Personally I have my doubts that this can really work well - but
    Robert> what is being proposed is an experiment, discovering whether
    Robert> things do work or not is what experiments are all about, so I see
    Robert> no problem with doing it (nor with publishing the doc that tells
    Robert> people how).
  
  The detector sounds like a DHCPv6 server to me.

]       ON HUMILITY: to err is human. To moo, bovine.           |  firewalls  [
]   Michael Richardson, Sandelman Software Works, Ottawa, ON    |net architect[
] mcr@sandelman.ottawa.on.ca http://www.sandelman.ottawa.on.ca/ |device driver[
] panic("Just another Debian GNU/Linux using, kernel hacking, security guy"); [
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.0.7 (GNU/Linux)
Comment: Finger me for keys

iQCVAwUBPkRT/4qHRg3pndX9AQHQ6gP/fYhWNYAlkTA7QH+K9kCgNMywRmEApcD+
GBfgcgdj6RjwP78QNLAcreHO3WPU/rvEjx4yL1EfLg7e8R++vjynyab+IBj2s3yH
bWOIslU//aGT3SjRiNJO6uvrkEkC55epLC3SI3qL41n+1Rjkf+cAu84VRsYZ1yCo
ca/56stsIHk=
=CZ1r
-----END PGP SIGNATURE-----

--
to unsubscribe send a message to namedroppers-request@ops.ietf.org with
the word 'unsubscribe' in a single line as the message text body.
archive: <http://ops.ietf.org/lists/namedroppers/>