Before we turn on anycasting for authdns, we'll want to create a mechanism for rotating ticket keys frequently and distributing them securely to tmpfs on the servers. This will allow session resumption to not be perturbed by anycast fluctuations.
Description
Description
Status | Subtype | Assigned | Task | ||
---|---|---|---|---|---|
Stalled | None | T81605 Offer AuthDNS service over IPv6 | |||
Open | None | T98006 Anycast AuthDNS | |||
Declined | None | T240863 Secure shared ticket key rotation for anycast authdns | |||
Open | None | T240866 Create a system for distributed shared secret material to server tmps |
Event Timeline
Comment Actions
There's not much DoTLS adoption so far, and really our primary HTTPS termination needs this more than AuthDNS does, at which point we can just copy whatever solution emerges there.