Tuesday, May 25, 2010

Re: [Geopriv] Security considerations for LIS discovery

On 25/05/2010 14:22, "Brian Rosen" <br@brianrosen.net> wrote:

> I am struggling a bit in understanding the problem.
>
> Let¹s start with why DHCP returns example.net and UNAPTR leads to
> lis.example.com. Why is that not fixable? What is hard about getting
> consistency in the domain names?

An ISP might have N customers for whom they run a LIS, but each of those
customers has their own domain name.

For provisioning purposes the customers would rather have the DHCP server
configured with a name that's under their control, with a NAPTR in their
(internal?) DNS pointing at their upstream LIS. The redirection might be
done directly, or they might use a non-terminal NAPTR pointing at
"lis.example.net". Then when they change ISP they only need change a single
DNS entry.

Also, please note that for the reverse-DNS mechanism proposed in
draft-thomson-geopriv-res-gw-lis-discovery there's no choice but to use the
domain name returned in the LIS URI - we certainly couldn't use
"z.y.x.w.in-addr.arpa".

Ray

_______________________________________________
Geopriv mailing list
Geopriv@ietf.org
https://www.ietf.org/mailman/listinfo/geopriv