On Mon, Jul 13, 2009 at 01:59:46PM +0200,
 Roy Arends <r...@dnss.ec> wrote 
 a message of 33 lines which said:

> SSAC's Report on DNS Response Modification
> http://www.icann.org/en/committees/security/sac032.pdf

Indeed. Good document. There is no need to discuss about
draft-livingood-dns-lie, all the issues raised here in this WG were
already in the SSAC document one year ago.

I regret one thing with SSAC 032: they mix wildcards in the zone and
lying resolvers. True, they have similarities but also differences
(for instance, wildcards in a zone follow the DNS protocol, and
therefore are compatible with DNSSEC) and I'm a bit tired of Slashdot
discussions starting with "Comcast == Sitefinder".

> IAB Commentary Architectural Concerns on the use of DNS Wildcards
> http://www.iab.org/documents/docs/2003-09-20-dns-wildcards.html

Irrelevant since it talks only about wildcards in the zone.

_______________________________________________
DNSOP mailing list
DNSOP@ietf.org
https://www.ietf.org/mailman/listinfo/dnsop

Reply via email to