On 2013-05-31, at 11:24, "Dobbins, Roland" <[email protected]> wrote:

> There's no crypto anything inherent in DNS today, heh.

Well, apart from the use of TSIG to authenticate zone transfers.

As I mentioned obliquely, I haven't heard of any widespread use of TSIG or 
SIG(0) to authenticate the channel between a stub resolver and a recursive 
resolver, but I'd hesitate to deny that there's any deployment without thinking 
of what numbers could possibly back up that claim.


Joe

_______________________________________________
dns-operations mailing list
[email protected]
https://lists.dns-oarc.net/mailman/listinfo/dns-operations
dns-jobs mailing list
https://lists.dns-oarc.net/mailman/listinfo/dns-jobs

Reply via email to