Re: DANE and DNSSEC adoption

2014-02-24 Thread /dev/rob0
On Mon, Feb 24, 2014 at 10:50:24PM +0100, Patrick Ben Koetter wrote: > * Viktor Dukhovni : > > On Mon, Feb 24, 2014 at 02:36:46PM -0700, LuKreme wrote: > > > unbound is better than bind for this sort of thing? (I noticed > > > freeBSD 10 has switched from bind to unbound, I expect they > > > have

Re: DANE and DNSSEC adoption

2014-02-24 Thread LuKreme
On 24 Feb 2014, at 14:43 , Viktor Dukhovni wrote: > Sure, you can validate other people's domains even if your own > domain is not signed. These are independent. Oh, right. Yes. OTHER people's domains. Never mind. :) -- Sometimes the only thing you could do for people was to be there. --Soul M

Re: DANE and DNSSEC adoption

2014-02-24 Thread Patrick Ben Koetter
* Viktor Dukhovni : > On Mon, Feb 24, 2014 at 02:36:46PM -0700, LuKreme wrote: > > > > Furthermore, you > > > can enable DNSSEC validation in your resolver before your own domain > > > is signed. The two are independent. > > > > Wait, what? You can? > > Sure, you can validate other people's dom

DANE and DNSSEC adoption

2014-02-24 Thread Viktor Dukhovni
On Mon, Feb 24, 2014 at 02:36:46PM -0700, LuKreme wrote: > > Furthermore, you > > can enable DNSSEC validation in your resolver before your own domain > > is signed. The two are independent. > > Wait, what? You can? Sure, you can validate other people's domains even if your own domain is not si