North American Network Operators Group

Date Prev | Date Next | Date Index | Thread Index | Author Index | Historical

Re: hat tip to .gov hostmasters

  • From: Mark Andrews
  • Date: Mon Sep 22 19:32:32 2008

In article <[email protected]> you write:
>* marcus sachs:
>
>> While we wait for applications to become DNSSEC-aware,
>
>Uhm, applications shouldn't be DNSSEC-aware.  Down that road lies
>madness.  What should an end user do when the browser tells him,
>"Warning: Could not validate DNSSEC signature on www.example.com,
>signature has expired.  Continue to connect?"

	The application just rejects the answer.  Trys again a
	couple of times then reports failure.  This is no different
	to the application talking to the validating resolver a
	couple of time and then reporting failure.

	The advantage of having the application do it is that you
	don't need to secure the connection between the validating
	resolver and the application.

	Mark