|
|||||||||||
|
[Users] freeS/WAN + DNSSec support
From: tim v. <prinski82(at)hotmail.com>
Date: Tue Mar 30 2004 - 21:14:52 EST Hi everyone, Ive got two questions relating to the use of IPSec and authenticating the IKE key exchange with public key encryption or digital signatures using DNSSec for storing and authentication of the needed public keys (and perhaps some other information). Specifically Id like to know how freeS/WAN supports the 2 scenarios proposed in http://perso.ens-lyon.fr/dominique.ponsard/ACTES/7_securite/paper.121.pdf. That paper is french but I will explain the point here, so theres no need for reading the paper.One solution to fetch the key and have it verified for authentication is to put a module in freeS/WAN that can do the verification of the authenticy of the keys and materials stored in DNSSec. The second one is to let the DNS cache do the verification and establishing an ipsec channel between the host and the DNS cache with the A-bit (« authenticated data ») on. So, does freeS/WAN support these 2 solutions and to what extent ?
I thought it might be usefull to take a look in the section about opportunistic encryption. I found there no specific answer except that OE relies on the principle of storing info and public keys in DNS. About authentication of dns data (DNSSec), I found « this authentication/authorization is only as strong as your DNS is secure. " I understand, but the use of DNSSec does still need one of the two above proposed solutions (which the ipsec software must support if DNSSec is used).
Other searches on « secure dns » and « dnssec » in the freeS/WAN docs didnt give me much usefull information about this issue.
Greetings, Tim Vissers Vraag van de week: Wat doe jij tegen spam, ongewenste e-mail? Received on Tue Mar 30 21:23:57 2004 This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 13:02:29 EDT |
||||||||||
|
|||||||||||