Welcome Back To IDN Forums - International Domain Name Forums - we are an Adsense Revenue Sharing Forum
IDN Forums - IDN Domains
IDN Domains
 

Go Back   IDN Forums - IDN Domains > International Domain Names > International Domain Name News
User Name
Password


Reply
 
Thread Tools Display Modes
  #1  
Old 11-03-2007, 01:26 PM
bwhhisc bwhhisc is offline
Super Moderator
 
Join Date: Dec 2005
Posts: 4,005
Rep Power: 0
bwhhisc is an unknown quantity at this point
"an astounding post by VeriSign's DNS expert, Dr. Phillip Hallam-Baker"

QUOTE:
We republish below an astounding post by VeriSign's DNS expert, Dr. Phillip Hallam-Baker, made on the IETF list. In it, he incisively describes the political implications of signing the root using DNSSEC, something we at IGP have been trying to do for about a year now. He also calls for sharing the signing authority, as IGP has also been doing. When we do this, we are sometimes accused of needlessly "politicizing" the issue. Wonder what they'll say now. Let's put Hallam-Baker on that IGF panel on "critical Internet resources" maybe, and see if his candor survives the glare of publicity?

http://blog.internetgovernance.org/b...9/3217425.html


AND FROM ANOTHER RELATED ARTICLE ON SAME (can be found at same link, scroll down):

The IGP Blog has a post about an important subject that is flying under too many radars, IANA's DNSSEC testbed signs root zone. I'll quote some key paragraphs, but it is worth reading the whole thing:

IANA is generating new zone signing keys (ZSK) monthly, using a script based upon Public-Key Cryptography Standards #11 as published by RSA. IANA maintains it is committed to make the sources of the system public. IANA's approach is to generate 3 overlapping ZSKs, one of which is "active" at any point and used to sign the root zone. The ZSKs are signed using one of 2 overlapping key signing keys (KSK), both of which sign the bundle of 3 ZSKs. In the event of emergency rollover, IANA relies upon a scripted procedure that migrates from the compromised key to the new, already "socialized" key. A status page for the testbed is available.

Based on this scant information, it does appear IANA is trying to move the ball forward on signing the root. However, the critical DNSSEC policy issue of who controls the root keys is still unresolved. It appears that control of both ZSKs and the KSKs (aka the "keys to the Internet kingdom") will reside with a USG contractor, just as suggested in the DHS sponsored root signing technical specification. This is sure to raise an eyebrow of some ccTLD and root operators and others who see DNSSEC as just one more way of solidifying the dominance of the ICANN/IANA root, and with it USG political oversight.

The above approach also goes against a basic tenant of Internet architecture of diversifying critical infrastructure in order to improve security and reliability (e.g., similar to how anycast technology diversifies some of the Internet's root servers). Maintaining all root zone signing activity with one root key operator (RKO) (as opposed to the IGP proposal of spreading it across a few non-governmental RKOs) seemingly violates this tenant, and certainly increases the probability that ICANN/IANA would be liable should it falter in performing it's DNSSEC related duties. Of course, this assumes that ICANN/IANA is willing to offer some level of reliability for signed DNS responses it provides. And if they're not, it's unclear why any other organization would be willing to stick it's neck out to provide DNSSEC based services dependent on the ICANN/IANA trust anchor.

Why is ICANN supporting the centralized solution? Because it expects to hold the keys.
One more reason why IANA should be spun off from ICANN!
Reply With Quote
Sponsored Links
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump




Powered by vBulletin Version 3.5.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 2.4.5
Style Design By: Resourcelabz.se
Copyright Urban Japan, Inc. 2005, 2006


1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99