As I said on the sunset4 mailing list this goes too far. I don't know about you but I want to be able to lookup TLSA records, SRV and other records types for foo.localhost and localhost.
And by the way this also requires a insecure delegation in the root zone for DNSSEC to work with validating client. This isn't a good idea. Mark -- Mark Andrews, ISC 1 Seymour St., Dundas Valley, NSW 2117, Australia PHONE: +61 2 9871 4742 INTERNET: ma...@isc.org _______________________________________________ DNSOP mailing list DNSOP@ietf.org https://www.ietf.org/mailman/listinfo/dnsop