<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>DNSSEC on Insinuator.net - Bold Statements</title>
    <link>https://insinuator.net/tags/dnssec/</link>
    <description>Recent content in DNSSEC on Insinuator.net - Bold Statements</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Tue, 03 Nov 2015 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://insinuator.net/tags/dnssec/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Some Notes on the “Drop IPv6 Fragments” vs. “This Will Break DNS[SEC]” Debate</title>
      <link>https://insinuator.net/2015/11/some-notes-on-the-drop-ipv6-fragments-vs.-this-will-break-dnssec-debate/</link>
      <pubDate>Tue, 03 Nov 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/11/some-notes-on-the-drop-ipv6-fragments-vs.-this-will-break-dnssec-debate/</guid>
      <description>&lt;p&gt;Some readers will probably be aware that we are amongst the proponents of a quite strict stance when it comes to filtering IPv6 packets with (certain) Extension Headers and/or fragmentation, because those can be the source of many security problems (as laid out &lt;a href=&#34;https://www.ernw.de/download/eu-14-Atlasis-Rey-Schaefer-briefings-Evasion-of-HighEnd-IPS-Devices-wp.pdf&#34;&gt;here&lt;/a&gt;, &lt;a href=&#34;http://gsec.hitb.org/materials/sg2015/D3%20-%20Marc%20Heuse%20-%20Hiding%20in%20Complexity.pdf&#34;&gt;here&lt;/a&gt; or &lt;a href=&#34;https://www.insinuator.net/2015/01/evasion-of-cisco-acls-by-abusing-ipv6-discussion-of-mitigation-techniques/&#34;&gt;here&lt;/a&gt;). Actually I still think it was a very good idea of, amongst others, Randy Bush and Ron Bonica to &lt;a href=&#34;https://tools.ietf.org/id/draft-bonica-6man-frag-deprecate-02.txt&#34;&gt;suggest the deprecation of IPv6 fragmentation in the IETF&lt;/a&gt;.&lt;br&gt;&#xA;On the other hand there are voices arguing that fragmented IPv6 packets will be needed in some cases, namely DNS[SEC]-related ones.&lt;br&gt;&#xA;In this post I will discuss some details of this debate (taking place in many circles, incl. &lt;a href=&#34;http://lists.si6networks.com/pipermail/ipv6hackers/2015-October/thread.html&#34;&gt;this thread&lt;/a&gt; on the &lt;em&gt;ipv6-hackers&lt;/em&gt; mailing list which, btw, &lt;a href=&#34;http://lists.si6networks.com/listinfo/ipv6hackers/&#34;&gt;you should subscribe to&lt;/a&gt;).&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
