Distribution trimmed down to just dnsop, where the question is most
pertinent.

Paul Wouters writes:
> Of course even better is using RFC 7901 Chain Query and run the few
> signature validations yourself.

Related, is there any notable software out there that does 7901?  I
started implementing it into BIND at a Hackthon several years ago
because I did think it would be useful to have.  

I got the scaffolding all set up for it, but then ran headlong into my
need to learn the finer points of the BIND DNSSEC internals and how I
would go about building up a list of the necessary records and fetch
any that were missing.

Then the Hackathon was over and I just put the whole thing aside.  Now
I only occasionally think about it, but never even far enough to look
into whether it's finally been done.

So, where is it implemented?

_______________________________________________
DNSOP mailing list -- dnsop@ietf.org
To unsubscribe send an email to dnsop-le...@ietf.org

Reply via email to