Re: DNSKEY Validation

2009-07-15 Thread Chris Thompson
On Jul 14 2009, Mark Elkins wrote: On Tue, 2009-07-14 at 17:50 +1000, Mark Andrews wrote: In message <1247555725.13064.4.ca...@ilinux>, Mark Elkins writes: > OK - so I accept that the algorithm will change. > > What about some sort of validation of the base-64 part of the key? > Is there a ch

Re: DNSKEY Validation

2009-07-14 Thread Mark Elkins
On Tue, 2009-07-14 at 17:50 +1000, Mark Andrews wrote: > In message <1247555725.13064.4.ca...@ilinux>, Mark Elkins writes: > > OK - so I accept that the algorithm will change. > > > > What about some sort of validation of the base-64 part of the key? > > Is there a checksum byte/word? > > Is there

Re: DNSKEY Validation

2009-07-14 Thread Mark Andrews
In message <1247555725.13064.4.ca...@ilinux>, Mark Elkins writes: > OK - so I accept that the algorithm will change. > > What about some sort of validation of the base-64 part of the key? > Is there a checksum byte/word? > Is there a way of checking that the length is correct? Have you thought o

Re: DNSKEY Validation

2009-07-14 Thread Mark Elkins
OK - so I accept that the algorithm will change. What about some sort of validation of the base-64 part of the key? Is there a checksum byte/word? Is there a way of checking that the length is correct? On Tue, 2009-07-14 at 10:56 +1000, Mark Andrews wrote: > In message <4a5b1bdc.3090...@gis.net>,

Re: DNSKEY Validation

2009-07-13 Thread Mark Andrews
In message <4a5b1bdc.3090...@gis.net>, Danny Mayer writes: > Stephane Bortzmeyer wrote: > > On Sun, Jul 12, 2009 at 08:42:27PM +0200, > > Mark Elkins wrote > > a message of 31 lines which said: > > > >> Arg 3 should be 5 (or maybe 3) - the algorithm. > > > > No, you must bnot use a h

Re: DNSKEY Validation

2009-07-13 Thread Danny Mayer
Stephane Bortzmeyer wrote: > On Sun, Jul 12, 2009 at 08:42:27PM +0200, > Mark Elkins wrote > a message of 31 lines which said: > >> Arg 3 should be 5 (or maybe 3) - the algorithm. > > No, you must bnot use a hard-wired list in your code, because the list > of algorithmps registered at

Re: DNSKEY Validation

2009-07-12 Thread Stephane Bortzmeyer
On Sun, Jul 12, 2009 at 08:42:27PM +0200, Mark Elkins wrote a message of 31 lines which said: > Arg 3 should be 5 (or maybe 3) - the algorithm. No, you must bnot use a hard-wired list in your code, because the list of algorithmps registered at IANA can change. > Can I glean a domain

DNSKEY Validation

2009-07-12 Thread Mark Elkins
I'm writing some DNSKEY Verification code in PHP If I am given ... 257 3 5 BQEBoURzbExxQ7B7dwyYIxLKdCUWDrbvBsLOsDvKO2hmJdrzSYIV gd8m +scQO2zD2U6Uw5cL7E+QRCJl48pcA+7k6uuTwSdS11CAR1MkvwC1 NDVmR6vHSp55qKIhov4QljLr66BAYT2K9o0O/+JBhimjAGQ+IUBFMmwB f5lk57YX9T8= (a valid - I hope - dnskey for cozates