Re: [DNSOP] Call for Adoption draft-wouters-sury-dnsop-algorithm-update

2017-03-02 Thread Roy Arends
> On 1 Mar 2017, at 17:41, Paul Wouters wrote: > > On Wed, 1 Mar 2017, Roy Arends wrote: > >> An attacker needs two successive 512 bit blocks and a prefix. >> However, you _do_ hash a chain of records. Forget CNAME, take a DNSKEY RRset >> with a few DNSKEY records in it. A fake 1024 bit key a

Re: [DNSOP] Call for Adoption draft-wouters-sury-dnsop-algorithm-update

2017-03-02 Thread Tony Finch
Roy Arends wrote: > > This is not true. The shattered.io pdf files contain an embedded jpeg. > The difference between the files is in the jpeg comment. The size of the > difference is 128 bytes. These are two consecutive 64 byte inputs. The > two versions hash to the same output, given the prefix.

Re: [DNSOP] Call for Adoption draft-wouters-sury-dnsop-algorithm-update

2017-03-02 Thread Paul Wouters
On Thu, 2 Mar 2017, Roy Arends wrote: Implementer should follow spec. Spec sez MUST or SHOULD. Implementers may decide to implent some algorithms and not some others, depending on the level. Now it says MUST- MUST+ MUST SHOULD- SHOULD+ and SHOULD. Very confusing. I understand _you_ find it

[DNSOP] I-D Action: draft-ietf-dnsop-no-response-issue-07.txt

2017-03-02 Thread internet-drafts
A New Internet-Draft is available from the on-line Internet-Drafts directories. This draft is a work item of the Domain Name System Operations of the IETF. Title : A Common Operational Problem in DNS Servers - Failure To Respond. Author : M. Andrews Fil

Re: [DNSOP] I-D Action: draft-ietf-dnsop-no-response-issue-07.txt

2017-03-02 Thread Mark Andrews
This adds descriptions of each test using words in addition to DiG commands. Mark -- Mark Andrews, ISC 1 Seymour St., Dundas Valley, NSW 2117, Australia PHONE: +61 2 9871 4742 INTERNET: ma...@isc.org ___ DNSOP mailing list DNSOP@ietf.o