Firewall Wizards mailing list archives
RE: Allowing DNS servers to operate behind NetScreen 500
From: "Reckhard, Tobias" <tobias.reckhard () secunet com>
Date: Fri, 14 Feb 2003 08:58:41 +0100
On Thursday, February 13, 2003 3:39 AM, Rob Payne
[mailto:rnspayne () the-paynes com] wrote:
Nothing personal to anyone, but a lot of firewalls really need to get these kinds of things right. If they do not, firewalls are going to get in the way of (DNS) security when zones start getting signed. (Rhetorical: Has anyone attempted to fit current DNS data plus RSA/SHA1 keys and signatures in packets 512 datagrams long?)
The question is when will DNS RRs ever get signed, if at all. The sheer amount of queries and number of records being requested, as well as the tremendous increase in payload due to signatures appears to create very real, practical problems. See http://cr.yp.to/djbdns/forgery.html and http://cr.yp.to/talks/2003dnssec.pdf. Cheers, Tobias _______________________________________________ firewall-wizards mailing list firewall-wizards () honor icsalabs com http://honor.icsalabs.com/mailman/listinfo/firewall-wizards
Current thread:
- Allowing DNS servers to operate behind NetScreen 500 Gebhart, Glenn (Feb 03)
- <Possible follow-ups>
- RE: Allowing DNS servers to operate behind NetScreen 500 David Klein (Feb 03)
- Re: Allowing DNS servers to operate behind NetScreen 500 Ben Nagy (Feb 04)
- Re: Allowing DNS servers to operate behind NetScreen 500 Rob Payne (Feb 13)
- Re: Allowing DNS servers to operate behind NetScreen 500 Ben Nagy (Feb 04)
- RE: Allowing DNS servers to operate behind NetScreen 500 David Klein (Feb 04)
- Re: Allowing DNS servers to operate behind NetScreen 500 Ben Nagy (Feb 04)
- RE: Allowing DNS servers to operate behind NetScreen 500 Reckhard, Tobias (Feb 14)
- Re: Allowing DNS servers to operate behind NetScreen 500 Rob Payne (Feb 14)
- Re: Allowing DNS servers to operate behind NetScreen 500 tqbf (Feb 15)
- Re: Allowing DNS servers to operate behind NetScreen 500 Paul D. Robertson (Feb 15)
- Re: Allowing DNS servers to operate behind NetScreen 500 Rob Payne (Feb 15)
- Re: DNS vs. Bernstein tqbf (Feb 15)
- Re: DNS and Firewalls Rob Payne (Feb 20)
- Re: DNS Extensions and Firewalls Thomas H. Ptacek (Feb 21)
- Re: DNS Extensions and Firewalls Frank Knobbe (Feb 22)
- Re: Allowing DNS servers to operate behind NetScreen 500 Rob Payne (Feb 14)
- Re: Allowing DNS servers to operate behind NetScreen 500 Volker Tanger (Feb 17)