New ZeroConf Spec

Dan Kegel dank at kegel.com
Sat Jul 22 23:43:21 BST 2006


On 7/22/06, Andrew Jorgensen <andrew.jorgensen at gmail.com> wrote:
> > Exactly my point: Avahi over SSL with some keys-based security layer
> > would make me feel a lot more comfortable.
> ...
> Some kind of shared key might be nice if you wanted a little extra
> security but when you start talking about that you're really talking
> about redesigning mDNS so that it's something other than what it is.

Not if you use IPSec to do the security.

> That discussion doesn't belong here and doesn't help figure out what
> to do for Edgy.

It bloody well does.  If turning on IPSec is (part of) the only way to make
mDNS safe, then we should either discuss how to do the needed
IPSec setup painlessly, or we should not deploy mDNS.
- Dan



More information about the ubuntu-devel mailing list