Re: [DNSOP] [Ext] on private use TLDS: .interNAL -> .LAN

2024-02-27 Thread Toerless Eckert
Thanks, Paul My comment: https://www.icann.org/en/public-comment/proceeding/proposed-top-level-domain-string-for-private-use-24-01-2024/submissions/eckert-toerless-27-02-2024 Summary of Submission: I would like to see a BCP RFC on the use of the "internal" TLD, and ICANN shou

Re: [DNSOP] [Ext] on private use TLDS: .interNAL -> .LAN

2024-02-27 Thread Toerless Eckert
On Tue, Feb 27, 2024 at 01:48:22PM +0100, Joe Abley wrote: > Hey, > > Op 27 feb 2024 om 12:08 heeft Toerless Eckert het volgende > geschreven: > > > I would like to see a BCP RFC on the use of the "internal" TLD, > > and ICANN should not finaliz

Re: [DNSOP] [Ext] on private use TLDS: .interNAL -> .LAN

2024-02-27 Thread Toerless Eckert
Me ? No. On Tue, Feb 27, 2024 at 01:22:43PM -0500, John Levine wrote: > It appears that Joe Abley said: > >Hey, > > > >Op 27 feb 2024 om 12:08 heeft Toerless Eckert het volgende > >geschreven: > > > >> I would like to see a BCP RFC on the use o

[DNSOP] DNSOP: question about hardening "something like mDNS" against attacks

2020-10-25 Thread Toerless Eckert
Ben Kaduk (SEC AD) was wondering about the appropriateness of a hardening suggestion in draft-ietf-anima-autonomic-control-plane-29. Let me translate this into mDNS, even though its about GRASP, but IMHO for the purpose of this issue its equivalent: Node wants to discover on a LAN a particular se

Re: [DNSOP] DNSOP: question about hardening "something like mDNS" against attacks

2020-10-26 Thread Toerless Eckert
. > > Of course there always has to be a trust establishment process, like BRSKI. > > I???m sure that something similar can be done with anima. > > > On Oct 25, 2020, at 15:25, Toerless Eckert wrote: > > > > ???Ben Kaduk (SEC AD) was wondering about the ap

Re: [DNSOP] DNSOP: question about hardening "something like mDNS" against attacks

2020-10-26 Thread Toerless Eckert
On Mon, Oct 26, 2020 at 01:05:42PM -0400, Ted Lemon wrote: > On Oct 26, 2020, at 12:59 PM, Toerless Eckert wrote: > > The networks where i am worried are not home networks, > > but something like an office park network, where supposedly each > > tenant (company) should have

Re: [DNSOP] DNSOP: question about hardening "something like mDNS" against attacks

2020-10-26 Thread Toerless Eckert
Toerless On Mon, Oct 26, 2020 at 01:11:33PM -0400, Jared Mauch wrote: > > > > On Oct 26, 2020, at 1:05 PM, Ted Lemon wrote: > > > > On Oct 26, 2020, at 12:59 PM, Toerless Eckert wrote: > >> The networks where i am worried are not home networks, > >&

Re: [DNSOP] DNSOP: question about hardening "something like mDNS" against attacks

2020-10-26 Thread Toerless Eckert
On Mon, Oct 26, 2020 at 04:09:41PM -0400, Ted Lemon wrote: > On Oct 26, 2020, at 4:05 PM, Jared Mauch wrote: > >> If the anwer of the experts is "do not harden implementations of existing > >> protocols", > >> but only improve protocols or eliminate security risks from underlays, i > >> think >

Re: [DNSOP] DNSOP: question about hardening "something like mDNS" against attacks

2020-10-26 Thread Toerless Eckert
On Mon, Oct 26, 2020 at 04:39:10PM -0400, Ted Lemon wrote: > On Oct 26, 2020, at 4:14 PM, Toerless Eckert wrote: > > And the question from the AD was what could be done. So, do you have any > > implemention suggestion ? Are there any sugestions for mDNS ? > > There are no s

[DNSOP] Anycast and DNS questions

2014-08-06 Thread Toerless Eckert
Sorry, haven't been following this group for a long time, so please excuse if answers to these questions have been discussed in before: a) What documents beside RFC3258 are describing any uses/procedures for having DNS servers use an anycast address to receive and respond to requests ? b)

Re: [DNSOP] Anycast and DNS questions

2014-08-06 Thread Toerless Eckert
Thanks, Patrick, inline On Wed, Aug 06, 2014 at 08:10:19AM -0400, Patrick W. Gilmore wrote: > > > > a) What documents beside RFC3258 are describing any uses/procedures > > for having DNS servers use an anycast address to receive and respond to > > requests ? > > Dunno, but something tells m

Re: [DNSOP] Anycast and DNS questions

2014-08-06 Thread Toerless Eckert
Hah! i am using that NTP one, but it didn't come to mind when asking the question. Have to read up on that AS112. Thanks Thanks! On Wed, Aug 06, 2014 at 02:09:18PM +0100, Tony Finch wrote: > Toerless Eckert wrote: > > > > b) How common are deployments in which the inf