Re: [DNSOP] I think we may have a solution - DNSCurve

2008-08-31 Thread bert hubert
On Sun, Aug 31, 2008 at 01:21:31PM -0700, David Conrad wrote: > are easier now then they were when I had a couple of lawyers look at > it for DNSSEC (which doesn't have encryption)) and it may or may not Technically, this may be true - but I got into trouble over an AES-based random generator,

Re: [DNSOP] I think we may have a solution - DNSCurve

2008-08-31 Thread David Conrad
> 1. no trust anchors in design, signatures seems to be loosely > connected. > 2. In it's ideal state it would change DNS to DNS over DNS-TXT. > 3. Requirements on aDNS server computation power is raised. > 4. I am not sure if labels like [...] make things more simpler. 5. I suspect having encry

Re: [DNSOP] I think we may have a solution - DNSCurve

2008-08-31 Thread Ondřej Surý
2008/8/31 Joe Baptista <[EMAIL PROTECTED]>: > http://dnscurve.org/ > > comments? I already made comments on namedroppers, so I will summarize it here: 1. no trust anchors in design, signatures seems to be loosely connected. Djb added page for TLD operators today, where he proposes signing .com