1 |
hi, |
2 |
|
3 |
> > i am just curious: how are you using DNSSEC? Or what for? |
4 |
> |
5 |
> Just for some extra security over certain parts of our dns |
6 |
> infrastructure at work, nothing amazing. |
7 |
|
8 |
okay, but how does DNSSEC help you establish that? and what is it that |
9 |
you are securing... |
10 |
|
11 |
i don't know much about DNSSEC, but |
12 |
from my understanding can DNSSEC establish cryptographic authority about |
13 |
a DNS record, iff you can trust the master of the zone. since non of |
14 |
the root servers supports DNSSEC, your zone can still be subject to |
15 |
forgery... |
16 |
|
17 |
or are you running your own root zone? i guess using split-horizon |
18 |
resolvers could be another setup in which this would work... ? |
19 |
|
20 |
regards |
21 |
thilo |
22 |
-- |
23 |
gentoo-server@g.o mailing list |