[107998] in North American Network Operators' Group

home help back first fref pref prev next nref lref last post

Re: hat tip to .gov hostmasters

daemon@ATHENA.MIT.EDU (Florian Weimer)
Mon Sep 22 11:26:23 2008

To: <marcus.sachs@verizon.com>
From: Florian Weimer <fweimer@bfk.de>
Date: Mon, 22 Sep 2008 17:24:00 +0200
In-Reply-To: <6BCAB7B989C2EA4AAD36652C14D4FB4563512B@FHDP1CCMXCV02.us.one.verizon.com>
	(marcus sachs's message of "Mon, 22 Sep 2008 11:16:20 -0400")
Cc: nanog@nanog.org
Errors-To: nanog-bounces@nanog.org

* marcus sachs:

> While we wait for applications to become DNSSEC-aware,

Uhm, applications shouldn't be DNSSEC-aware.  Down that road lies
madness.  What should an end user do when the browser tells him,
"Warning: Could not validate DNSSEC signature on www.example.com,
signature has expired.  Continue to connect?"

--=20
Florian Weimer                <fweimer@bfk.de>
BFK edv-consulting GmbH       http://www.bfk.de/
Kriegsstra=DFe 100              tel: +49-721-96201-1
D-76133 Karlsruhe             fax: +49-721-96201-99


home help back first fref pref prev next nref lref last post