nanog mailing list archives
Re: IPv6 Confusion
From: David Conrad <drc () virtualized org>
Date: Tue, 17 Feb 2009 15:20:39 -1000
On Feb 17, 2009, at 1:55 PM, Mark Andrews wrote:
(which was never fully thought out -- how does a autoconfig'd device get a DNS name associated with their address in a DNSSEC-signed world again?) andletting network operators use DHCP with IPv6 the way they do with IPv4.David you know as well as I do that DNSSEC is a orthognal issue here.
My understanding, which may well be wrong, is that:- stateless auto-configuration assumes the client will update the address to name association once it has obtained the address.
- In order to do this, the DNS server needs to support Dynamic DNS. - If DNSSEC is in use, it requires the use of on-line signing keys. - Security folks get unhappy when you mention on-line signing keys. Solution? - Don't have address to name associations- Don't worry about (or accept lesser) security on address to name associations.
Of course the DNSSEC bit is sort of moot, as I suspect there aren't a whole lot of ISPs in a position to support dynamic updates from clients...
Regards, -drc
Current thread:
- Re: IPv6 Confusion, (continued)
- Re: IPv6 Confusion David Barak (Feb 18)
- RE: IPv6 Confusion Tony Hain (Feb 18)
- Re: IPv6 Confusion David Conrad (Feb 18)
- Re: IPv6 Confusion Randy Bush (Feb 18)
- Re: IPv6 Confusion Nick Hilliard (Feb 19)
- RE: IPv6 Confusion Tony Hain (Feb 19)
- Re: IPv6 Confusion Mark Andrews (Feb 17)
- Re: IPv6 Confusion Valdis . Kletnieks (Feb 17)
- Re: IPv6 Confusion Mark Andrews (Feb 17)
- Re: IPv6 Confusion Leen Besselink (Feb 17)
- Re: IPv6 Confusion David Conrad (Feb 17)
- Re: IPv6 Confusion Mark Andrews (Feb 17)
- Re: IPv6 Confusion David Conrad (Feb 17)
- Re: IPv6 Confusion Zaid Ali (Feb 17)
- Re: IPv6 Confusion Randy Bush (Feb 17)
- Re: IPv6 Confusion Mark Andrews (Feb 17)
- Re: IPv6 Confusion Nathan Ward (Feb 17)
- Re: IPv6 Confusion Joe Provo (Feb 17)
- RE: IPv6 Confusion Tony Hain (Feb 17)
- Re: IPv6 Confusion Randy Bush (Feb 17)
- RE: IPv6 Confusion Steven Lisson (Feb 17)