Florian Weimer wrote: > ... > > Because DNSSEC does not prevent cache poisoning, it only detects it.
i do not understand this statement. > ... In retrospect, not signing delegations and glue was a huge mistake. one of many. but we're 17 years into the dnssec experience, so starting over is either contraindicated or our only salvation, depending.
_______________________________________________ dns-operations mailing list dns-operations@lists.dns-oarc.net https://lists.dns-oarc.net/mailman/listinfo/dns-operations dns-jobs mailing list https://lists.dns-oarc.net/mailman/listinfo/dns-jobs