> David Conrad wrote: > > > Given this, does anyone see any DNS security and/or stability concerns > > if a miracle were to happen and the root were to be signed tomorrow? > > Well,it will introduce a lot of large RRs, which may cause problems. > > Considering that two RRs each containing 2048 bit data will need > oversized messages, they may not be properly treated by some > servers. > > Those suffering from oversized messages may turn-off DNSSEC and there > is instability for those moving with their laptops.
And how is this different from the answers from TLDs which have already turned on DNSSEC? > Masataka Ohta > > _______________________________________________ > DNSOP mailing list > DNSOP@ietf.org > https://www.ietf.org/mailman/listinfo/dnsop -- Mark Andrews, ISC 1 Seymour St., Dundas Valley, NSW 2117, Australia PHONE: +61 2 9871 4742 INTERNET: [EMAIL PROTECTED] _______________________________________________ DNSOP mailing list DNSOP@ietf.org https://www.ietf.org/mailman/listinfo/dnsop