[107998] in North American Network Operators' Group
Re: hat tip to .gov hostmasters
daemon@ATHENA.MIT.EDU (Florian Weimer)
Mon Sep 22 11:26:23 2008
To: <marcus.sachs@verizon.com>
From: Florian Weimer <fweimer@bfk.de>
Date: Mon, 22 Sep 2008 17:24:00 +0200
In-Reply-To: <6BCAB7B989C2EA4AAD36652C14D4FB4563512B@FHDP1CCMXCV02.us.one.verizon.com>
(marcus sachs's message of "Mon, 22 Sep 2008 11:16:20 -0400")
Cc: nanog@nanog.org
Errors-To: nanog-bounces@nanog.org
* marcus sachs:
> While we wait for applications to become DNSSEC-aware,
Uhm, applications shouldn't be DNSSEC-aware. Down that road lies
madness. What should an end user do when the browser tells him,
"Warning: Could not validate DNSSEC signature on www.example.com,
signature has expired. Continue to connect?"
--=20
Florian Weimer <fweimer@bfk.de>
BFK edv-consulting GmbH http://www.bfk.de/
Kriegsstra=DFe 100 tel: +49-721-96201-1
D-76133 Karlsruhe fax: +49-721-96201-99