On Nov 4, 2009, at 11:41 AM, Matthew Dempsky wrote: > On Wed, Nov 4, 2009 at 11:26 AM, <[email protected]> wrote: >> The current deployment plan is to stage things to push out large >> responses >> early - prior to having any actual DNSSEC usable data ... ostensibly >> to >> flush out DNSmtu problems. > > Is this plan to push out large responses indiscriminately, or only in > response to queries with DO=1?
We're not planning on breaking the DNS protocol. DNSSEC responses will only be provided if DO=1 (currently about 70% of the queries hitting the root have DO=1). Regards, -drc _______________________________________________ DNSOP mailing list [email protected] https://www.ietf.org/mailman/listinfo/dnsop
