On Nov 22, 2018, at 00:03, Warren Kumari <[email protected]> wrote: > > > > I am sympathetic to the general use case, but really don't want this to open > scary security holes / decrease "trust" in DNSSEC.
By not allowing VPNs to use an enterprise internal dnssec trust anchor, you also erode trust in dnssec, or end up not using dnssec internally at all when connected via VPN. I suggest you wait for me to push -15 before asking dnsop. It should be out today or tomorrow and contains quite some changes related to this topic. Paul
_______________________________________________ IPsec mailing list [email protected] https://www.ietf.org/mailman/listinfo/ipsec
