> David Conrad wrote:
> 
> > Given this, does anyone see any DNS security and/or stability concerns  
> > if a miracle were to happen and the root were to be signed tomorrow?
> 
> Well,it will introduce a lot of large RRs, which may cause problems.
> 
> Considering that two RRs each containing 2048 bit data will need
> oversized messages, they may not be properly treated by some
> servers.
> 
> Those suffering from oversized messages may turn-off DNSSEC and there
> is instability for those moving with their laptops.

        And how is this different from the answers from TLDs which
        have already turned on DNSSEC?

>                                                       Masataka Ohta
> 
> _______________________________________________
> DNSOP mailing list
> DNSOP@ietf.org
> https://www.ietf.org/mailman/listinfo/dnsop
-- 
Mark Andrews, ISC
1 Seymour St., Dundas Valley, NSW 2117, Australia
PHONE: +61 2 9871 4742                 INTERNET: [EMAIL PROTECTED]
_______________________________________________
DNSOP mailing list
DNSOP@ietf.org
https://www.ietf.org/mailman/listinfo/dnsop

Reply via email to