On 01/14/2014 04:43 PM, Doug Barton wrote:
Other than the DS records (if any) the records associated with a given TLD (specifically the NS records) in the root are not signed.
... obviously the glue records are not signed either of course. My point was that it's the delegation that some paranoid countries don't want removed, and DNSSEC isn't going to help that.
Doug _______________________________________________ DNSOP mailing list DNSOP@ietf.org https://www.ietf.org/mailman/listinfo/dnsop