DNSSEC for squid

From: Willi Herzig <wher_at_herzigs.de>
Date: Mon, 10 Nov 2008 14:54:33 +0100

Hello,

is there any support of squid to validate DNS queries using DNSSEC (DNS
Security Extensions)? Or is it planned?

Why?
DNSSEC was designed to protect the Internet from certain attacks, such
as DNS cache poisoning(see also the Kaminsky attach).
TLD .SE ist already DNSSEC ready. ICANN pushes pushes .ORG forward with
DNSSEC.

It would be very useful if squid validates DNS queries using DNSSEC (for
example using a library like libval) and shows the result as an error
message if there are any problems with this domain.
Without DNSSEC support the user will just get the message "Could not get
an IP address SERVER ERROR" without knowing that the name exists, but
there was just an error validation the domain (for example a cache
poisoning attack).

Looking http://www.dnssec-deployment.org/tracker/ there seems to be a
lot of software supporting DNSSEC.

Thanks for your help.

Regards

        Willi Herzig
Received on Mon Nov 10 2008 - 20:42:08 MST

This archive was generated by hypermail 2.2.0 : Tue Nov 11 2008 - 12:00:03 MST