> On Aug 12, 2015, at 7:23 AM, Andrew Sullivan wrote:
>
> On Wed, Aug 12, 2015 at 07:27:53AM +0100, Miek Gieben wrote:
>> So we are in agreement that glibc's stub resolver is acting really dumb here?
>
> I think that's overstating it. It appears that glibc implemented the
> protocol according
I'm reading 4641bis after a really long time and the current version appears
useful and very well done. So I'd like to applaud the editors and working group
for bringing this document into such good shape.
Leaving aside the nits, here are some of my comments on -11.
3.2.1. Rolling a KSK that
Some comments on draft-ietf-dnsop-dnssec-trust-anchor-01:
Section 2, last para
# A validating resolver MAY support
#configuration using a truncated DS hash value as a human-factors
#convenience: shorter strings are easier to type and less prone to
#error when entered man