[129014] in North American Network Operators' Group
Re: DNSSEC and SSL
daemon@ATHENA.MIT.EDU (Wes Hardaker)
Mon Aug 23 10:31:50 2010
From: Wes Hardaker <wjhns61@hardakers.net>
To: Mans Nilsson <mansaxel@besserwisser.org>
Date: Mon, 23 Aug 2010 07:31:36 -0700
In-Reply-To: <20100822195727.GA26860@besserwisser.org> (Mans Nilsson's message
of "Sun, 22 Aug 2010 21:57:27 +0200")
Cc: "nanog@nanog.org" <nanog@nanog.org>
Errors-To: nanog-bounces+nanog.discuss=bloom-picayune.mit.edu@nanog.org
>>>>> On Sun, 22 Aug 2010 21:57:27 +0200, Mans Nilsson <mansaxel@besserwisser.org> said:
MN> The best option today is to run a full-service resolver on the host;
The DNSSEC-Tools project has instrumented a large number of applications
with an in-application validating resolver. Including OpenSSH (with a
new auto-accept-keys option!), sendmail, postfix, libspf, thunderbird,
lftp, wget, ncftp, ...
--
Wes Hardaker
My Pictures: http://capturedonearth.com/
My Thoughts: http://pontifications.hardakers.net/