The DNSSEC Root Signing Ceremony
cloudflare.com
The DNSSEC Root Signing Ceremony
1–10 of 49 posts
Re: The DNSSEC Root Signing Ceremony
#2The Ceremony Administrator
An Internal Witness
The Credentials Safe Controller
The Hardware Safe Controller
Crypto Officer #1
Crypto Officer #2
Crypto Officer #3
Fascinating. What's the signing ceremony for .IO look like? .COM? .NET? .CO.UK? .COM.AU?
Re: The DNSSEC Root Signing Ceremony
#3Access requires the cooperation of 7 individuals, all of whom must be present for a Root Signing Ceremony to take place: The Ceremony Administrator An Internal Witness The Credentials Safe Controller The Hardware Safe Controller Crypto Officer #1 Crypto Officer #2 Crypto Officer #3 Fascinating. What's the signing ceremony for .IO look like? .COM? .NET? .CO.UK? .COM.AU?
Re: The DNSSEC Root Signing Ceremony
#4Re: The DNSSEC Root Signing Ceremony
#5Re: The DNSSEC Root Signing Ceremony
#6So how is this logically different than the replacement of all CAs with a single one?
http://sockpuppet.org/blog/2015/01/15/against-dnssec/
DNSSEC does seem pretty unnecessary at this point for security. It hands more power over the internet to fewer hands, whilst not providing any improved security.
Re: The DNSSEC Root Signing Ceremony
#7Access requires the cooperation of 7 individuals, all of whom must be present for a Root Signing Ceremony to take place: The Ceremony Administrator An Internal Witness The Credentials Safe Controller The Hardware Safe Controller Crypto Officer #1 Crypto Officer #2 Crypto Officer #3 Fascinating. What's the signing ceremony for .IO look like? .COM? .NET? .CO.UK? .COM.AU?
Re: The DNSSEC Root Signing Ceremony
#8So how is this logically different than the replacement of all CAs with a single one?
This was talked about a lot on the last DNSSEC story on HN. I don't have a link to the story but this site was linked to from discussions. http://sockpuppet.org/blog/2015/01/15/against-dnssec/ DNSSEC does seem pretty unnecessary at this point for security. It hands more power over the internet to fewer hands, whilst not providing any improved security.
Re: The DNSSEC Root Signing Ceremony
#9So how is this logically different than the replacement of all CAs with a single one?
A traditional CA validates empirically that a customer controls a domain at some point in time. DNSSEC is a stronger validation of control of the domain, because it's a property of the domain itself.
Trusting the domain registry to indicate who controls a domain makes a lot more sense to me than trusting a third party. If I can't trust the DS records, I can't trust the NS records either.
A DS record doesn't indicate a connection between an organization and a domain though, which a traditional CA supposedly might.
Re: The DNSSEC Root Signing Ceremony
#10So how is this logically different than the replacement of all CAs with a single one?
This was talked about a lot on the last DNSSEC story on HN. I don't have a link to the story but this site was linked to from discussions. http://sockpuppet.org/blog/2015/01/15/against-dnssec/ DNSSEC does seem pretty unnecessary at this point for security. It hands more power over the internet to fewer hands, whilst not providing any improved security.