On 2 May 2025, at 01:14, Mark Andrews <ma...@isc.org> wrote:

> A DNAME does not break the DNSSEC chain of trust.  An insecure delegation is 
> needed to do that.

Yes. I was just reminding people of the mechanism we decided was sensible to 
add zones to the AS112 project. I agree that it's not a useful idea in this 
case.

> “Black hole servers” can be any set of servers.

Yes, but I'm aware that to a lot of people "black hole servers" means exactly 
AS112. Other examples of this assumption in the IETF have resulted in lame 
delegations to the AS112 servers. 


Joe

_______________________________________________
DNSOP mailing list -- dnsop@ietf.org
To unsubscribe send an email to dnsop-le...@ietf.org

Reply via email to