hi,

> > i am just curious: how are you using DNSSEC? Or what for?
>
> Just for some extra security over certain parts of our dns
> infrastructure at work, nothing amazing.

okay, but how does DNSSEC help you establish that? and what is it that 
you are securing...

i don't know much about DNSSEC, but
from my understanding can DNSSEC establish cryptographic authority about 
a DNS record, iff you can trust the master of the zone. since non of 
the root servers supports DNSSEC, your zone can still be subject to 
forgery...

or are you running your own root zone? i guess using split-horizon 
resolvers could be another setup in which this would work... ?

regards
thilo
-- 
[email protected] mailing list

Reply via email to