[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: How do we get the whole world to upgrade to DNSSEC capable resolvers?



[no hat]

On Fri, Jul 25, 2008 at 03:36:15PM -0400, Joe Abley wrote:

> It seems to me that a bare validator, freshly started, with no cache and no 
> special configuration, knows nothing about what zones in the world are 
> secured and which are not.

I thought, in any case, that the hypothetical case you were talking
about was a laptop in a hotel room.  Sure, there are people on this
list who know how to set up and configure a full validating resolver
for these purposes.  But the stub resolver is still dependent on
what's upstream, and that's what's going to be on a laptop, I think.
So if the compromise is on the network between the stub and the
validator, you're hosed.  (I thought this was the point someone
up-thread was making.  No?)

A

-- 
Andrew Sullivan
ajs@commandprompt.com
+1 503 667 4564 x104
http://www.commandprompt.com/

--
to unsubscribe send a message to namedroppers-request@ops.ietf.org with
the word 'unsubscribe' in a single line as the message text body.
archive: <http://ops.ietf.org/lists/namedroppers/>