Pantek Library
Hosting Provided By
CybrHost
High Speed Hosting

[Design] Re: lookup of self-TXT/KEY

From: D. Hugh Redelmeier <hugh(at)mimosa.com>
Date: Mon Mar 10 2003 - 15:12:27 EST


-----BEGIN PGP SIGNED MESSAGE-----
| From: Michael Richardson <mcr@sandelman.ottawa.on.ca>

| DHR, 1) do you require that you find both the TXT and the KEY record for
| a host-only OE, or will KEY suffice?

The intent is that Pluto will only initiate OE if it can see sufficient credentials in DNS for the other side to respond.

For an initiation on behalf of itself, a KEY is sufficient.

For an initiation on behalf of a client behind, TXT is required and, if the TXT does not contain the public key, a KEY is also required.

| 2) is there a way to override this?

Not currently.

| 3) Will it retry?

Do you need help?X

No. This is part of a general (planned to be fixed) lack of retrying.

| The problem that I get is that the DNS query to lookup self may itself
| cause OE, and may fail, and if it does, then we won't do OE again.

Remember that there is a single thread of queries currently. So the initial queries will fail in a predictable order. Blast a hole to a nice DNS *first* (a lame workaround, not a solution).

The other side will probably have a go at OE if it is configured suitably. So all is not lost.

Hugh Redelmeier
hugh@mimosa.com voice: +1 416 482-8253

-----BEGIN PGP SIGNATURE-----
Version: 2.6.3ia
Charset: noconv

iQCVAwUBPmzxssFAuQPManGZAQFxTwQArOvNJPP3dJsHXwL+6m0qKb5NsJdLG+Re hY4hAFm18p7Y4z4fBvjeoH+zWzeJkK3VeyvYDFCokevNnHrz5vbSEL8XTZrO+IH+ g6m1tulvQJpPMIk9OhrjDqZhpnr+k4iuANoAreEre8nBMf+0dUruRnxPl4ItBBBT 1tnUD7O4K3Q=
=/3/e
-----END PGP SIGNATURE-----



Design mailing list
Design@lists.freeswan.org
http://lists.freeswan.org/mailman/listinfo/design Received on Tue Mar 11 19:34:24 2003

This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 12:59:57 EDT

Do you need more help?X

Contact Us  Legal Notices  Order Services Online 
Pantek Home  Privacy Policy  IT news  Site Map  Pantek Library