On Tue, Nov 12, 2013 at 11:29:12PM -0800, Christian Huitema <[email protected]> wrote a message of 51 lines which said:
> It does require that the resolver somehow learn the "zone cuts," but > that is not impossible to learn. Specially since every DNSSEC-validating resolver has to do it, anyway (to know where to find the DS and the DNSKEY). So, in practice, BIND and Unbound has this code for a long time. _______________________________________________ perpass mailing list [email protected] https://www.ietf.org/mailman/listinfo/perpass
