Development issues regarding the cerowrt test router project
 help / color / mirror / Atom feed
From: Valdis.Kletnieks@vt.edu
To: Chuck Anderson <cra@WPI.EDU>
Cc: cerowrt-devel@lists.bufferbloat.net
Subject: Re: [Cerowrt-devel] DNSSEC & NTP Bootstrapping
Date: Mon, 24 Mar 2014 09:54:47 -0400	[thread overview]
Message-ID: <230052.1395669287@turing-police.cc.vt.edu> (raw)
In-Reply-To: Your message of "Mon, 24 Mar 2014 08:29:16 -0400." <20140324122915.GP7867@angus.ind.WPI.EDU>

[-- Attachment #1: Type: text/plain, Size: 796 bytes --]

On Mon, 24 Mar 2014 08:29:16 -0400, Chuck Anderson said:

> How about writing an RFC to define a well-known NTP anycast address
> and using that as a fallback?  This is a problem that needs to be
> solved for the larger internet community, not just CeroWRT/OpenWRT.

Using a well-known anycast address for NTP is somewhat problematic for security.
It's possible to secure anycast DNS using DNSSEC - but the NTP crypto isn't
suitable for securing an anycast mode.

Fortunately, for many use cases, we can probably rely on the upstream
provider to hand us an NTP server address in a DHCP extension.  If you're
willing to trust the *rest* of that DHCP response, you may as well trust the
NTP server it points you at.

I admit not having a clever idea for the non-DHCP case though...

[-- Attachment #2: Type: application/pgp-signature, Size: 848 bytes --]

  parent reply	other threads:[~2014-03-24 13:55 UTC|newest]

Thread overview: 51+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2014-03-22  3:33 Joseph Swick
2014-03-22 17:42 ` Dave Taht
2014-03-22 18:43   ` Simon Kelley
2014-03-22 19:38     ` Toke Høiland-Jørgensen
2014-03-22 19:42       ` Simon Kelley
2014-03-22 20:00         ` Toke Høiland-Jørgensen
2014-03-24 21:39           ` Simon Kelley
2014-03-27 20:38           ` Simon Kelley
2014-03-28  7:57             ` Toke Høiland-Jørgensen
2014-03-28  9:08               ` Simon Kelley
2014-03-28  9:18                 ` Toke Høiland-Jørgensen
2014-03-28 10:41                   ` Simon Kelley
2014-03-28 10:48                     ` Toke Høiland-Jørgensen
2014-03-28 19:46                       ` Simon Kelley
2014-03-28 20:55                       ` Simon Kelley
2014-03-29  9:20                         ` Toke Høiland-Jørgensen
2014-03-29 10:55                           ` [Cerowrt-devel] DNSSEC & NTP Bootstrapping -- prototype! Toke Høiland-Jørgensen
2014-03-29 21:21                             ` Michael Richardson
2014-03-29 21:30                               ` Dave Taht
2014-03-30 13:21                                 ` Toke Høiland-Jørgensen
2014-03-30 16:59                                   ` Dave Taht
2014-03-30 18:38                                     ` Toke Høiland-Jørgensen
2014-03-30 19:30                                   ` Toke Høiland-Jørgensen
2014-03-30 20:06                                     ` Dave Taht
2014-03-30 20:51                                       ` Toke Høiland-Jørgensen
2014-03-31 12:42                                         ` Robert Bradley
2014-03-31 17:26                                           ` Robert Bradley
2014-03-22 21:15   ` [Cerowrt-devel] DNSSEC & NTP Bootstrapping Joseph Swick
2014-03-23 10:12     ` Aaron Wood
2014-03-23 11:15       ` Toke Høiland-Jørgensen
2014-03-23 12:11         ` David Personette
2014-03-23 12:20           ` Toke Høiland-Jørgensen
2014-03-23 12:22         ` Aaron Wood
2014-03-23 22:41           ` Michael Richardson
2014-03-24  9:51             ` Aaron Wood
2014-03-24  9:59               ` Toke Høiland-Jørgensen
2014-03-24 12:29                 ` Chuck Anderson
2014-03-24 13:39                   ` Toke Høiland-Jørgensen
2014-03-24 14:31                     ` Alijah Ballard
2014-03-24 13:54                   ` Valdis.Kletnieks [this message]
2014-03-24 19:12 ` Phil Pennock
2014-03-24 20:27   ` David Personette
2014-03-24 21:30     ` Phil Pennock
2014-03-24 21:58     ` Dave Taht
2014-03-25  9:55       ` David Personette
2014-03-25 14:25       ` Michael Richardson
2014-03-24 21:03   ` Toke Høiland-Jørgensen
2014-03-24 22:09     ` Török Edwin
2014-03-24 23:33       ` Toke Høiland-Jørgensen
2014-03-25  1:16         ` Joseph Swick
2014-03-24 22:16     ` Phil Pennock

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

  List information: https://lists.bufferbloat.net/postorius/lists/cerowrt-devel.lists.bufferbloat.net/

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=230052.1395669287@turing-police.cc.vt.edu \
    --to=valdis.kletnieks@vt.edu \
    --cc=cerowrt-devel@lists.bufferbloat.net \
    --cc=cra@WPI.EDU \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox