dnssec

D. Stussy spam at bde-arc.ampr.org
Sun Jul 27 04:00:49 UTC 2008


"Wolfgang S. Rupprecht" <wolfgang.rupprecht+gnus200807 at gmail.com> wrote in
message news:g6d760$2b1m$1 at sf1.isc.org...
> All this talk of spoofing attacks got me to get off my duff and
> configure dnssec for the ~dozen zones I'm authoritative for.  Sadly it ...
>
> The question is, what is the hang up?

A good, secondary reason is that the cost of authentication is privacy.  The
implementation basically reveals the full contents of a zone, and some
people just don't like that.

A third reason is that not enough of the process is automated.  Too much of
it must be manually performed.




More information about the bind-users mailing list