Hello, I revised my draft-rafiee-intarea-cga-tsig incorporating your comments that I received by email. Please review my revised document. Best Regards, Hosnieh
URL: http://www.ietf.org/internet-drafts/draft-rafiee-intarea-cga-tsig-01.txt Status: http://datatracker.ietf.org/doc/draft-rafiee-intarea-cga-tsig Htmlized: http://tools.ietf.org/html/draft-rafiee-intarea-cga-tsig-01 Diff: http://www.ietf.org/rfcdiff?url2=draft-rafiee-intarea-cga-tsig-01 Abstract: The first step in the Transaction SIGnature (TSIG) (RFC 2845) process is the generation of a shared secret to be used between a DNS server and a host. The second step is the manual exchange of the shared secret between the DNS server and the host. This document, CGA-TSIG, proposes a possible way to automate the now manual process used for the authentication of a node with a DNS server during the DNS Update process by using the same parameters as are used in generating a secure address in IPv6 networks, i.e., Cryptographically Generated Addresses (CGA) (RFC 3972). CGA-TSIG facilitates this authentication process and reduces the time needed for DNS Updates. The current signature generation process and verification mechanism in TSIG are thus replaced with CGA. This algorithm is added, as an extension, to TSIG to eliminate the human intervention needed for generation and exchange of keys between a DNS server and a host when SEcure Neighbor Discovery (SEND) (RFC 3971) is used. The IETF Secretariat _______________________________________________ DNSOP mailing list DNSOP@ietf.org https://www.ietf.org/mailman/listinfo/dnsop