On 3/13/2017 4:11 AM, Paul Wouters wrote:
The draft breaks DNSSEC.
...
I have proposed a method that would not change the RPZ response for a non-DNSSEC client, but would add data for DNSSEC capable clients to be
That sounds like an excellent bit of technical enhancement to consider... /after/ documenting /existing/ practice.
d/ -- Dave Crocker Brandenburg InternetWorking bbiw.net _______________________________________________ DNSOP mailing list DNSOP@ietf.org https://www.ietf.org/mailman/listinfo/dnsop