On 21.6.2018 18:46, Shumon Huque wrote:
> On Thu, Jun 21, 2018 at 2:19 AM Petr Špaček <petr.spa...@nic.cz
> <mailto:petr.spa...@nic.cz>> wrote:
> 
> 
>     HTTPS over TLS is what we did for root zone import into Knot Resolver's
>     cache (from version 2.3 onwards but beware, there are little bugs which
>     were fixed in 2.4 - to be released soon).
> 
> 
> Out of curiosity, which HTTPS source are you using for the root zone import?

It is user configurable and examples in docs
http://knot-resolver.readthedocs.io/en/latest/modules.html#cache-prefilling
use
https://www.internic.net/domain/root.zone

After download the data are DNSSEC validated and inserted into cache.

-- 
Petr Špaček  @  CZ.NIC

_______________________________________________
DNSOP mailing list
DNSOP@ietf.org
https://www.ietf.org/mailman/listinfo/dnsop

Reply via email to