On 22/01/2020 17:13, Tony Finch wrote: > Are there any registries that configure secure delegations from DNSKEY > records (and do their own conversion to DS records) rather than accepting > DS records from the registrant? I think I have heard that .de is one.
CA (IIRC they require both the key and DS, probably to double check the DS themselves), BE and EU are some example that comes immediately to mind. There are others. DE is definitively one also. -- Patrick Mevzek _______________________________________________ dns-operations mailing list dns-operations@lists.dns-oarc.net https://lists.dns-oarc.net/mailman/listinfo/dns-operations