Does OpenSSL perform internal DNSSEC validation for DANE TLSA records?
25.8K reputation · 12 Aug 2020, 14:31 UTC
DANE Validation and DNSSEC Dependency
OpenSSL provides experimental support for DNS-based Authentication of Named Entities (DANE) via the -dane flag in s_client. This feature allows the client to retrieve TLSA records to verify TLS certificates, reducing reliance on traditional Certificate Authorities.
A critical requirement for DANE security is the authenticity of the DNS records, which is typically ensured via DNSSEC. However, there is uncertainty regarding how OpenSSL handles the verification of these records when the underlying system resolver is a non-validating stub resolver.
If the library delegates the lookup to the OS resolver without performing its own DNSSEC validation, the security guarantees of DANE may be bypassed if the resolver does not provide proof of authenticity.
Technical Questions
- Does OpenSSL implement an internal DNSSEC validator to verify TLSA records, or does it rely entirely on the OS resolver's response?
- In the event that a resolver returns a TLSA record without DNSSEC validation, does OpenSSL treat the record as insecure or accept it as valid?