Re: DNSSEC architecture vs reality

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 




On 4/12/21 5:39 AM, Petite Abeille wrote:

On Apr 12, 2021, at 14:25, Keith Moore <moore@xxxxxxxxxxxxxxxxxxxx> wrote:

Thanks for the update.   It looks as if progress is indeed being made.   Now I wonder: what is being done to publicize DNSSEC to try to get wider adoption?
As it stands — one has to get out of its way to find it.

dnsimple has good support for it out-of-the-box:

https://support.dnsimple.com/articles/dnssec/

https://dnssec-analyzer.verisignlabs.com/textprotocol.com
https://dnssec-analyzer.verisignlabs.com/textprotocol.net

One of the interesting revelations is that:

1) Google implemented DANE at one point in Chrome

2) Google doesn't currently sign their zone

The implication being that it wasn't a very serious effort to see what would happen if they don't even sign their own domain.

Mike




[Index of Archives]     [IETF Annoucements]     [IETF]     [IP Storage]     [Yosemite News]     [Linux SCTP]     [Linux Newbies]     [Mhonarc]     [Fedora Users]

  Powered by Linux