At 9:15 AM +0200 7/16/09, Stephane Bortzmeyer wrote: >On Mon, Jul 13, 2009 at 01:59:46PM +0200, > Roy Arends <r...@dnss.ec> wrote > a message of 33 lines which said: > >> SSAC's Report on DNS Response Modification >> http://www.icann.org/en/committees/security/sac032.pdf > >Indeed. Good document. There is no need to discuss about >draft-livingood-dns-lie, all the issues raised here in this WG were >already in the SSAC document one year ago. > >I regret one thing with SSAC 032: they mix wildcards in the zone and >lying resolvers. True, they have similarities but also differences >(for instance, wildcards in a zone follow the DNS protocol, and >therefore are compatible with DNSSEC) and I'm a bit tired of Slashdot >discussions starting with "Comcast == Sitefinder".
I noticed this as well. Can someone from SSAC discuss here why that is the case? It is fairly relevant to this thread, given that a few people have wanted to see SAC032 discussed in the draft, but it doesn't seem relevant because of the difference. --Paul Hoffman, Director --VPN Consortium _______________________________________________ DNSOP mailing list DNSOP@ietf.org https://www.ietf.org/mailman/listinfo/dnsop