[129014] in North American Network Operators' Group

home help back first fref pref prev next nref lref last post

Re: DNSSEC and SSL

daemon@ATHENA.MIT.EDU (Wes Hardaker)
Mon Aug 23 10:31:50 2010

From: Wes Hardaker <wjhns61@hardakers.net>
To: Mans Nilsson <mansaxel@besserwisser.org>
Date: Mon, 23 Aug 2010 07:31:36 -0700
In-Reply-To: <20100822195727.GA26860@besserwisser.org> (Mans Nilsson's message
	of "Sun, 22 Aug 2010 21:57:27 +0200")
Cc: "nanog@nanog.org" <nanog@nanog.org>
Errors-To: nanog-bounces+nanog.discuss=bloom-picayune.mit.edu@nanog.org

>>>>> On Sun, 22 Aug 2010 21:57:27 +0200, Mans Nilsson <mansaxel@besserwisser.org> said:

MN> The best option today is to run a full-service resolver on the host;

The DNSSEC-Tools project has instrumented a large number of applications
with an in-application validating resolver.  Including OpenSSH (with a
new auto-accept-keys option!), sendmail, postfix, libspf, thunderbird,
lftp, wget, ncftp, ...
-- 
Wes Hardaker                                     
My Pictures:  http://capturedonearth.com/
My Thoughts:  http://pontifications.hardakers.net/


home help back first fref pref prev next nref lref last post