On Tue, 16 Sep 2003 09:59:40 PDT, [EMAIL PROTECTED] said: > DNSsec will work properly with wildcards, regardless of where they are > in the DNS.
Which means that a rogue DNS can lead you down the garden path and DNSsec won't give you a clue that you're being lied to. It's the same question as the "what happens to SSL to a phantom site?" - Verisign can provide an A record for the server and an SSL cert that will work.
pgp00000.pgp
Description: PGP signature
