←back to thread

246 points nh2 | 1 comments | | HN request time: 0s | source
Show context
ndsipa_pomu ◴[] No.41912342[source]
I prefer to assign an external name to an internal device and grab a free SSL cert from LetsEncrypt, but using DNS challenge instead as internal IP addresses aren't reachable by their servers.
replies(9): >>41912368 #>>41912827 #>>41913126 #>>41913387 #>>41913720 #>>41913826 #>>41916306 #>>41917079 #>>41917804 #
candiddevmike ◴[] No.41913126[source]
Obligatory if DNS validation is good enough, DANE should've been too. Yes, MITM things could potentially ensue on untrusted networks without DNSSEC, but that's perfect being the enemy of good territory IMO.

This would allow folks to have .internal with auto-discovered, decentralized, trusted PKI. It would also enable something like a DNSSEC on/off toggle switch for IoT devices to allow owners to MITM them and provide local functionality for their cloud services.

replies(3): >>41913298 #>>41914996 #>>41916478 #
ndsipa_pomu ◴[] No.41913298[source]
I hadn't heard of DANE, so looked it up and found the wikipedia entry: https://en.wikipedia.org/wiki/DNS-based_Authentication_of_Na...

According to that, it's not supported by Chrome, nor Firefox.

replies(2): >>41916498 #>>41917893 #
teddyh ◴[] No.41917893[source]
It’s customarily used for e-mail transport.
replies(1): >>41921257 #
tptacek ◴[] No.41921257[source]
No, it isn't; it can't be, because none of the major email domains are DNSSEC-signed to begin with.

Let me know if I've misunderstood your point, and there some other widespread niche usage DANE finds in SMTP.

replies(1): >>41926451 #
teddyh ◴[] No.41926451[source]
“Customarily” must not necessarily mean “major email domains”. As I understand it, DANE is commonly used by organizations wanting to secure e-mail between them; DANE enforcement is agreed by both parties, and then used without issue.
replies(1): >>41930841 #
wolf550e ◴[] No.41930841[source]
Didn't they invent MTA-STS so they could not use DANE? They use MTA-STS.
replies(1): >>41954625 #
teddyh ◴[] No.41954625[source]
I know that is what MTA-STS is for, but haven’t heard from people actually using it. I have, however, heard from people using DANE in the way i described.

(For those who don’t know, MTA-STS is basically DANE but for people who hate DNSSEC. And are OK with requiring every mail server to also have a web server running.)

replies(2): >>41956791 #>>42077147 #
1. teddyh ◴[] No.42077147{4}[source]
(This use of DANE is explicitly described in RFC 7672, section 6.)