North American Network Operators Group

Date Prev | Date Next | Date Index | Thread Index | Author Index | Historical

Re: hat tip to .gov hostmasters

  • From: bmanning
  • Date: Mon Sep 22 11:32:14 2008

On Mon, Sep 22, 2008 at 05:24:00PM +0200, Florian Weimer wrote:
> * marcus sachs:
> 
> > While we wait for applications to become DNSSEC-aware,
> 
> Uhm, applications shouldn't be DNSSEC-aware.  Down that road lies
> madness.  What should an end user do when the browser tells him,
> "Warning: Could not validate DNSSEC signature on www.example.com,
> signature has expired.  Continue to connect?"
> 
> -- 
> Florian Weimer                <fweimer@xxxxxx>


	actually, I am really hoping that at least one API
	is standardized so that applications can use DNSSEC 
	data.  We never finished the discussion on fail/open
	fail/closed wrt DNSSEC.

--bill