--On fredag, september 23, 2005 11:51:53 +0200 Stephane Bortzmeyer <[EMAIL PROTECTED]> wrote:

On Fri, Sep 23, 2005 at 08:44:44AM +0200,
 Harald Tveit Alvestrand <[EMAIL PROTECTED]> wrote
 a message of 21 lines which said:

If I'd had DNSSEC, and the people looking it up had had DNSSEC,

*And* if they knew that the zone should be signed (most zones will
not, during the transition and no DS would be there to tell it).

I don't consider that I "have" DNSSEC until I have a chain of signatures from a commonly known public key..... probably the root, but .org might be Good Enough for this particular instance..... until then, I consider everything I do "just experimenting".

YMMV.






.
dnsop resources:_____________________________________________________
web user interface: http://darkwing.uoregon.edu/~llynch/dnsop.html
mhonarc archive: http://darkwing.uoregon.edu/~llynch/dnsop/index.html

Reply via email to