On 2022-10-12 at 09:05:34 UTC-0400 (Wed, 12 Oct 2022 09:05:34 -0400) PGNet Dev <pgnet....@gmail.com> is rumored to have said:
*must* I sign my DNSSEC keys for my domains with the same algo in-use by the respective TLDs' roots in order to not fubar DANE usage specifically,
No.
or can I (arbitrarily) use any algo listed @ the iana.org link above, regardless of the root signing algo?
Yes. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Not Currently Available For Hire