On Nov 22, 2018, at 00:03, Warren Kumari <[email protected]> wrote:
> 
> 
> 
> I am sympathetic to the general use case, but really don't want this to open 
> scary security holes / decrease "trust" in DNSSEC.

By not allowing VPNs to use an enterprise internal dnssec trust anchor, you 
also erode trust in dnssec, or end up not using dnssec internally at all when 
connected via VPN.

I suggest you wait for me to push -15 before asking dnsop. It should be out 
today or tomorrow and contains quite some changes related to this topic.

Paul

_______________________________________________
IPsec mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/ipsec

Reply via email to