On Tue, Feb 16, 2021 at 9:01 AM Ben Schwartz <bemasc=
[email protected]> wrote:

>
>
> I think the scary part is that an authenticated TLS failure (due to
> misconfiguration, bug, overload, or rollback) results in an outage
>

Why is this scary? We have ample evidence that it's possible to run high
availability services using TLS at much larger scale than pretty much any
authoritative server.  I realize that this is outside of the experience of
some [0] DNS operators, but it's not like the knowledge isn't out there.

-Ekr

[0] Though not all. Cloudflare, for instance, runs an authoritative service.
_______________________________________________
dns-privacy mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/dns-privacy

Reply via email to