Presentation is loading. Please wait.

Presentation is loading. Please wait.

Forgery Resilience Phase #2 Ólafur Guðmundsson

Similar presentations


Presentation on theme: "Forgery Resilience Phase #2 Ólafur Guðmundsson"— Presentation transcript:

1 Forgery Resilience Phase #2 Ólafur Guðmundsson Ogud@ogud.com

2 What is coming How can an avalanche be stopped ? - Build fences - Run away - Ski faster - Pray - “Let it be!” - Deploy DNSSEC

3 Forgery-resilience-07 Passed WGLC will be sent to IESG next week. Expect RFC in about 4 months Deploy NOW !!!

4 Ideas? There are lots of them: –http://www.psg.com/lists/namedroppers/name droppers.2008/msg01131.htmlhttp://www.psg.com/lists/namedroppers/name droppers.2008/msg01131.html –X20 –QID –……

5 What else to do? Questions for people to think about: –What can be done in the short term ? –What can be done without updating software? –What can be done in the medium term ? –What work does DNSEXT or DNSOP need to do ?

6 DNS protocol economics 101 All changes have a “cost” –How high the cost is for Implementations Deployment if there are changes in operation Authorative DNS data providers DNS consumer i.e. resolvers Is there fall-back –When can this be deployed Standards action needed: add 8-24 months Code (add 1-24 months) Testing (add 1-12 months) Rollout (add 2-18 months) Fixes needed (add 1-24 months)

7 The plan The chairs will not propose a plan or officially adopt new work until the full details of the current scare are known.


Download ppt "Forgery Resilience Phase #2 Ólafur Guðmundsson"

Similar presentations


Ads by Google