MelindaShore / dnssec-serialization

Internet draft(s) proposing a standard for serialization and transport of dnssec/dane validation chains
0 stars 1 forks source link

SNI #1

Open MelindaShore opened 9 years ago

MelindaShore commented 9 years ago

Need to add some text requiring the chain lookup on SNI, if available.

MelindaShore commented 9 years ago

Still needs more discussion. From Viktor:

" I think the Section 4 SNI interaction would be a lot cleaner, if SNI is mandatory for clients that use the proposed extension. In which case the server can only respond with a leaf TLSA RRset (and chain of RRSIG/DNSKEY/DS/... records) whose "base domain" ( see section 3 of RFC6698 and soon definition of TLSA base domain in draft-ietf-dane-ops-13 (later this week)). Using some random name for the server's IP address is not a good idea IMHO. PTR records are too often poorly correlated with the client's notion of the target server name."

shuque commented 9 years ago

For the record, I completely agree with Viktor. But I'll defer to collective discussion and consensus on this issue.