hi, > > i am just curious: how are you using DNSSEC? Or what for? > > Just for some extra security over certain parts of our dns > infrastructure at work, nothing amazing.
okay, but how does DNSSEC help you establish that? and what is it that you are securing... i don't know much about DNSSEC, but from my understanding can DNSSEC establish cryptographic authority about a DNS record, iff you can trust the master of the zone. since non of the root servers supports DNSSEC, your zone can still be subject to forgery... or are you running your own root zone? i guess using split-horizon resolvers could be another setup in which this would work... ? regards thilo -- [email protected] mailing list
