Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Feasibility of requiring the protocol to prove that the encrypted and unencrypted resolvers are operated by the same entity #9

Closed
chris-box opened this issue Sep 3, 2020 · 2 comments
Labels

Comments

@chris-box
Copy link
Contributor

@chris-box chris-box commented Sep 3, 2020

How does the client learn the encrypted and unencrypted DNS servers are operated by the same administrative domain ?
The client can authenticate the encrypted DNS servers but cannot authenticate the unencrypted DNS server !

Originally posted by @tireddy2 in #2 (comment)

@chris-box
Copy link
Contributor Author

@chris-box chris-box commented Sep 3, 2020

If it is genuinely impossible to prove association between two resolvers when one resolver is unencrypted, then perhaps we should not have the concept at all. But I'm hoping it is not impossible.

@chris-box
Copy link
Contributor Author

@chris-box chris-box commented Nov 6, 2020

draft-pauly-add-deer-00 does this (at least in some circumstances), so it's not impossible.

@chris-box chris-box closed this Nov 6, 2020
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

1 participant