[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]


To: Simon Josefsson <simon+keydist@josefsson.org>
Cc: keydist@cafax.se
From: Randy Bush <randy@psg.com>
Date: Sat, 29 Dec 2001 16:12:47 -0800
Delivery-Date: Sun Dec 30 01:12:56 2001
Sender: owner-keydist@cafax.se
Subject: Re: What are we trying to do?

> _ssh.host.example.org.  IN [REFERRAL-RR] http://www.example.org/key.txt?hash=A61B2DF..

actually, i am still thinking more of using the dns only to locate the
service for all users and hosts in the domain.  e.g.

    _keys.psg.com     A      <my ldap server>

signed, of course

and having the ldap server be available only authed and crypted, and serving

  pgp keys
     randy  ...
     other ...
     ...
  host keys
     psg.com
     rip.psg.com
     roam.psg.com
     ...

and providing a <https://psg.com/keys/> server which would let non-ldap
folk see the data via web, and maybe let some of the users modify their
data.

randy

Home | Date list | Subject list