Re: [PATCH] Add support for ldns

This is a discussion on Re: [PATCH] Add support for ldns within the OpenSSH Development forums, part of the Networking and Network Related category; nobody on this one ? I really think autonomous signature validation capabilities are a useful feature in an ssh client. In ...


Go Back   Usenet Forums > Networking and Network Related > OpenSSH Development

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 05-29-2007
Simon Vallet
 
Posts: n/a
Default Re: [PATCH] Add support for ldns


nobody on this one ?

I really think autonomous signature validation capabilities are a useful
feature in an ssh client. In a mobile scenario, simply trusting the next
DNS hop seems only marginally better as having no signed records at all.

I'm willing to spend more time on this patch if necessary, so any
feedback is welcome

Simon

On Mon, 21 May 2007 15:55:07 +0200
Simon Vallet <svallet@genoscope.cns.fr> wrote:

> Hi,
>
> as discussed before, we're trying to make use of SSHFP records (RFC
> 4255) to publish host key fingerprints in the DNS.
>
> However, some non-OpenBSD platforms don't support DNSSEC in the native
> resolver (e.g. glibc), which renders the whole thing quite useless,
> since openssh correctly requires the RRs to be signed and validated.
>
> The following patch adds support for ldns, an external resolver
> library, with the following functionality:
> - Set DO on the SSHFP query
> - Support AD if the answer comes from a validating resolver
> - Support autonomous validation using a configured trust anchor in case
> the answer is not marked as authentic.
>
> It depends on the SVN version of ldns (revision 2345), which is available
> there: http://www.nlnetlabs.nl/ldns/

_______________________________________________
openssh-unix-dev mailing list
openssh-unix-dev@mindrot.org
http://lists.mindrot.org/mailman/lis...enssh-unix-dev
Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT +1. The time now is 10:31 AM.


Powered by vBulletin® Version 3.6.8
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0