Dear all, I have a question which may not relate with the WGLC of this document.
where is the validating resolver? it usally locates in the local host as the same as the normal resolver? or it usually locates in recursiver name server or some special host? if it usally locates in the local host as the same as the normal resolver, every machine must be configured at leat one trust anchor. so the local machine need a lot of computing resources to finish the resolving process. if it usually locates in recursiver name server or some special host, the local host just send a query to that machine. if so, the data transfered between the local lost and the resolver is not secured, we need another mechanism to secure the data transfer. Yao Jiankang _______________________________________________ DNSOP mailing list DNSOP@ietf.org https://www.ietf.org/mailman/listinfo/dnsop