There are many published papers about the load created by DNSSEC on
authoritative name servers. And a lot of practical experience as well,
some of it publically documented.

For the validating *resolvers*, I find on the Web a few tests in a lab
environment (setting up BIND or Unbound with and without validation,
and launching many DNS requests at them and measuring the differences)
but I do not find data about *actual* deployments, for instance an ISP
publishing the results of enabling validation ("We observed no
difference" or "We had to triple the number of boxes used as resolvers
because of the increased CPU load"). Any pointer?


_______________________________________________
dns-operations mailing list
dns-operations@lists.dns-oarc.net
https://lists.dns-oarc.net/mailman/listinfo/dns-operations
dns-jobs mailing list
https://lists.dns-oarc.net/mailman/listinfo/dns-jobs

Reply via email to