On 11/6/17, 10:57, "DNSOP on behalf of Petr Špaček" wrote:
>I did my best to explain my reasoning, let me know if you can see some holes
>in the reasoning.
Coming from my assumption that "use any chain" is the best way to go, I tried
to figure out why you are coming to a different conclusion.
On Wed, 8 Nov 2017, Edward Lewis wrote:
This is why the guidance in "Protocol Modifications for the DNS Security Extensions" leads to
"any" chain. "Clarifications and Implementation Notes for DNS Security (DNSSEC)" opens
the possibility that knobs can be included, which is the prerogative of t