We discuss what the DANE technology for authenticating domain names via DNS entails and why it has not gained widespread adoption in browsers.
/ Unsplash /
What is DANE
Certificate Authorities (CAs) are organizations that certifying cryptographic . They affix their electronic signature, confirming authenticity. However, there can be situations where certificates are issued improperly. For example, last year Google initiated a 'trust termination' process for Symantec certificates due to their compromise (we covered this story in our blog — en ).
To prevent such situations, a few years ago, IETF the DANE technology (but it has not seen widespread adoption in browsers — we will discuss why further).
DANE (DNS-based Authentication of Named Entities) is a set of specifications that allows using DNSSEC (Domain Name System Security Extensions) to control the validity of SSL certificates. DNSSEC is an extension for the domain name system that minimizes address substitution attacks. By using these two technologies, a webmaster or client can reach one of the DNS zone operators and confirm the validity of the certificate in use.
Essentially, DANE acts as a self-signed certificate (its reliability is guaranteed by DNSSEC) and supplements the functions of CAs.
Hoe het werkt
The DANE specification is described in . According to the document, a new type was added to the — TLSA. It contains information about the transmitted certificate, dimensions and type of transmitted data, as well as the data itself. The webmaster creates a digital fingerprint of the certificate, signs it with DNSSEC, and publishes it in TLSA.
The client connects to the website and compares its certificate with the 'copy' received from the DNS operator. If they match, the resource is considered trusted.
On the DANE wiki page, the following example DNS request is provided to the server example.org on TCP port 443:
IN TLSA _443._tcp.example.orgThe response looks like this:
_443._tcp.example.com. IN TLSA (
3 0 0 30820307308201efa003020102020... )
DANE has several extensions that work with other DNS records besides TLSA. The first is the DNS record SSHFP for key verification during SSH connections. This is described in , en . Het tweede is een OPENPGPKEY-record voor het uitwisselen van sleutels via PGP (). Ten slotte is het derde een SMIMEA-record (de standaard in de RFC is niet officieel, er is alleen ) voor cryptografische sleuteluitwisseling via S/MIME.
Wat is het probleem met DANE
In het midden van mei vond de DNS-OARC-conferentie plaats (dit is een non-profitorganisatie die zich bezighoudt met kwesties van veiligheid, stabiliteit en ontwikkeling van het domeinnaamsysteem). Op een van de panels kwamen de experts , dat de DANE-technologie in browsers faalde (tenzij we kijken naar de huidige implementatie). Geoff Huston, een senior researcher , een van de vijf regionale internetregisters, over DANE als een 'dode technologie'.
Populaire browsers ondersteunen geen certificaatauthenticatie via DANE. Op de markt , die de functionaliteit van TLSA-records blootleggen, maar ook hun ondersteuning .
De problemen met de verspreiding van DANE in browsers worden in verband gebracht met de lange validatieprocessen via DNSSEC. Het systeem moet cryptografische berekeningen uitvoeren om de authenticiteit van het SSL-certificaat te bevestigen en moet tijdens de eerste verbinding met de bron de hele keten van DNS-servers doorlopen (van de rootzone tot het hostdomein).

/ Unsplash /
Deze tekortkoming probeerden ze in Mozilla op te lossen met behulp van de voor TLS. Dit moest het aantal DNS-records verminderen dat de client tijdens de authenticatie moest doornemen. Echter, binnen de ontwikkelaarsgroep ontstonden meningsverschillen die niet opgelost konden worden. Uiteindelijk werd het project stopgezet, hoewel het in maart 2018 door de IETF was goedgekeurd.
Een andere reden voor de lage populariteit van DANE is de beperkte verspreiding van DNSSEC in de wereld — . Experts hebben vastgesteld dat dit onvoldoende is voor een actieve promotie van DANE.
Waarschijnlijk zal de industrie zich in een andere richting ontwikkelen. In plaats van DNS te gebruiken voor de verificatie van SSL/TLS-certificaten, zullen marktspelers daarentegen de protocollen DNS-over-TLS (DoT) en DNS-over-HTTPS (DoH) promoten. Laatstgenoemde hebben we genoemd in een van onze op Habr. Ze coderen en controleren gebruikersverzoeken naar de DNS-server, waardoor kwaadwillenden geen kans krijgen om gegevens te vervalsen. Begin dit jaar heeft DoT al in Google voor zijn openbare DNS. Wat betreft DANE - of de technologie 'terug op de been' kan komen en toch massaal kan worden, zal in de toekomst moeten blijken.
Wat hebben we nog meer voor verdere lectuur:
![]()
![]()
![]()
![]()
![]()
![]()
![]()
Bron: habr.com
