DNS Extensions working group V.Dolmatov, Ed.
Internet-Draft Cryptocom Ltd.
-Intended status: Standards Track November 10, 2009
-Expires: May 10, 2010
+Intended status: Standards Track November 22, 2009
+Expires: May 22, 2010
Use of GOST signature algorithms in DNSKEY and RRSIG Resource Records
for DNSSEC
- draft-ietf-dnsext-dnssec-gost-03
+ draft-ietf-dnsext-dnssec-gost-04
Status of this Memo
the Domain Name System Security Extensions (DNSSEC, RFC 4033,
RFC 4034, and RFC 4035).
-V.Dolmatov Expires May 10, 2010 [Page 1]
+V.Dolmatov Expires May 22, 2010 [Page 1]
Table of Contents
"SHOULD", "SHOULD NOT", "RECOMMENDED", "MAY", and "OPTIONAL" in this
document are to be interpreted as described in [RFC2119].
-V.Dolmatov Expires May 10, 2010 [Page 2]
+V.Dolmatov Expires May 22, 2010 [Page 2]
2. DNSKEY Resource Records
GostAsn1: MEUCAQAwHAYGKoUDAgITMBIGByqFAwICIwEGByqFAwICHgEEIgQgV/S
2FXdMtzKJBehZvjF4lVSx6m66TwqSe/MFwKSH/3E=
-V.Dolmatov Expires May 10, 2010 [Page 3]
+V.Dolmatov Expires May 22, 2010 [Page 3]
The following DNSKEY RR stores a DNS zone key for example.net
type {TBA2}. The wire format of a digest value is compatible with
RFC 4490 [RFC4490], that is digest is in little-endian representation.
-V.Dolmatov Expires May 10, 2010 [Page 4]
+V.Dolmatov Expires May 22, 2010 [Page 4]
The digest MUST always be calculated with GOST R 34.11-94 parameters
identified by id-GostR3411-94-CryptoProParamSet [RFC4357].
Currently, the cryptographic resistance of the GOST 34.10-2001
digital signature algorithm is estimated as 2**128 operations
of multiple elliptic curve point computations on prime modulus
- 2**256.
+ of order 2**256.
-V.Dolmatov Expires May 10, 2010 [Page 5]
+V.Dolmatov Expires May 22, 2010 [Page 5]
Currently, the cryptographic resistance of GOST 34.11-94 hash
algorithm is estimated as 2**128 operations of computations of a
Rose, "Resource Records for the DNS Security Extensions",
RFC 4034, March 2005.
-V.Dolmatov Expires May 10, 2010 [Page 6]
+V.Dolmatov Expires May 22, 2010 [Page 6]
[RFC4035] Arends R., Austein R., Larson M., Massey D., and S.
Rose, "Protocol Modifications for the DNS Security
EMail: igus@cryptocom.ru
-V.Dolmatov Expires May 10, 2010 [Page 8]
+V.Dolmatov Expires May 22, 2010 [Page 8]
+