On 21.6.2018 18:46, Shumon Huque wrote: > On Thu, Jun 21, 2018 at 2:19 AM Petr Špaček <petr.spa...@nic.cz > <mailto:petr.spa...@nic.cz>> wrote: > > > HTTPS over TLS is what we did for root zone import into Knot Resolver's > cache (from version 2.3 onwards but beware, there are little bugs which > were fixed in 2.4 - to be released soon). > > > Out of curiosity, which HTTPS source are you using for the root zone import?
It is user configurable and examples in docs http://knot-resolver.readthedocs.io/en/latest/modules.html#cache-prefilling use https://www.internic.net/domain/root.zone After download the data are DNSSEC validated and inserted into cache. -- Petr Špaček @ CZ.NIC _______________________________________________ DNSOP mailing list DNSOP@ietf.org https://www.ietf.org/mailman/listinfo/dnsop