On Fri, Jul 27, 2018 at 02:18:46PM +1000, Mark Andrews wrote:
>       just because A => B, it doesn’t mean that !B => !A.

(... it does mean that, actually.)

> On 27 Jul 2018, at 2:13 pm, Davey Song <[email protected]> wrote:
>  I mean zone digest is not for zone transimition with channel security. On 
> page 4, the authors compare zone digest and Channel security.

I think this is meant to explain why channel security mechanisms like
TLS have limitations, and ZONEMD can do even more.

But that doesn't mean the use cases for ZONEMD is restricted to the ones
not handled by TLS.  You can use ZONEMD with AXFR, too.

-- 
Evan Hunt -- [email protected]
Internet Systems Consortium, Inc.

_______________________________________________
DNSOP mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/dnsop

Reply via email to