On 2 May 2025, at 01:14, Mark Andrews <ma...@isc.org> wrote: > A DNAME does not break the DNSSEC chain of trust. An insecure delegation is > needed to do that.
Yes. I was just reminding people of the mechanism we decided was sensible to add zones to the AS112 project. I agree that it's not a useful idea in this case. > “Black hole servers” can be any set of servers. Yes, but I'm aware that to a lot of people "black hole servers" means exactly AS112. Other examples of this assumption in the IETF have resulted in lame delegations to the AS112 servers. Joe _______________________________________________ DNSOP mailing list -- dnsop@ietf.org To unsubscribe send an email to dnsop-le...@ietf.org