nanog mailing list archives

Re: howto deploy DNSSEC [was: Re: wrt joao damas' DLV talk on wednesday]


From: Randy Bush <randy () psg com>
Date: Tue, 13 Jun 2006 19:12:07 -0700


please refrain from this thread -- a few folks are attempting to move 
DNSSEC ahead; we will fail, but would appreciate any constructive 
criticism on the pitfalls to deploy before we are all dead.

i am amazed that you do not consider open discussion of security
policies and procedures to be used in the deployment of a security
protocol to be constructive.

imiho, over the years, dnssec has repeatedly suffered from not
facing the reality of the sticky bits of deployment.  so you may
have to suffer folk discussing this, even though it may detract
from dnssec marketing.

randy


Current thread: