Hello Andreas, [email protected] writes:
> > I doubt this is easy useable with DNSSEC as DNS records are created > on-the-fly, no? it is possible to do the DNS64 synthesizing of records after doing the DNSSEC validation. As long as the client application does not do DNSSEC validation, the scheme works. But sure, DNS64 and DNSSEC do not play well together. > I also don't like the idea of yet another workaround > to delay the switch-over, after all we already have > dual-stack(protocol) for the next decade i suspect. DNS64 enables a network to go IPv6 native all the way, and switch off legacy IPv4. I see that DNS64 *helps* with the switch over, it *helps* sun-setting IPv4. It reduces complexity by removing the need to run full dual-stack in order to access legacy IPv4 resources on the Internet. -- Carsten Strotmann Email: [email protected] Blog: strotmann.de _______________________________________________ Unbound-users mailing list [email protected] http://unbound.nlnetlabs.nl/mailman/listinfo/unbound-users
