Re: DNSSEC architecture vs reality (was: Re: Quic: the elephant in the room)

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 




On 4/11/21 4:57 PM, Keith Moore wrote:


What's the immediate benefit to the signer from signing one's own RRs?   (Note: if nothing is verifying signatures, the immediate benefit is zero.)

If a major browser vendor started using it to their advantage for faster session startup, you're now creating a reason to deploy. DNS manifestly works well enough in its "trust but verify" mode with webpki, but if you change some external things like speeding up serving up ads, etc hopefully ears will perk up.

Half of the battle with standards is answering the question "why should i care" with things that involve $$$.

Mike




[Index of Archives]     [IETF Annoucements]     [IETF]     [IP Storage]     [Yosemite News]     [Linux SCTP]     [Linux Newbies]     [Mhonarc]     [Fedora Users]

  Powered by Linux