On Sat, 23 Mar 2019 at 14:08, Paul Vixie <p...@redbarn.org> wrote: > Bind9 with no config file now does the right recursive thing, including > dnssec. Knot and unbound and powerdns will not be far behind. We just need > to get the word out, to ISPs, Enterprise, SOHO, and end users of Windows, > macosx, Linux, and BSD. The hard part will be iOS and Android, due to the > permission model and app stores. Those can be last. >
There are rumours that Apple is at least considering DANE implementations[0] for their mobile and desktop browsers. If that comes to pass you'll see DNSSEC validation on iOS a lot sooner than you think. Anyone who has any customer influence with Apple could possibly push them in that direction... enough large customers pushing might inch them toward that ledge. [0]: < https://lists.dns-oarc.net/pipermail/dns-operations/2019-January/018298.html >
_______________________________________________ DNSOP mailing list DNSOP@ietf.org https://www.ietf.org/mailman/listinfo/dnsop