Florian Weimer wrote:
> ...
>
> Because DNSSEC does not prevent cache poisoning, it only detects it.

i do not understand this statement.

> ... In retrospect, not signing delegations and glue was a huge mistake.

one of many. but we're 17 years into the dnssec experience, so starting
over is either contraindicated or our only salvation, depending.

_______________________________________________
dns-operations mailing list
dns-operations@lists.dns-oarc.net
https://lists.dns-oarc.net/mailman/listinfo/dns-operations
dns-jobs mailing list
https://lists.dns-oarc.net/mailman/listinfo/dns-jobs

Reply via email to