[DNSOP] Re: QName Minimization vs Aggressive NSEC vs Encrypt ed and Authenticated DNS vs Serve Stale vs DNSSEC vs LocalRoot

Roy Arends <[email protected]>
Newsgroups gmane.ietf.dnsop
Message-ID <[email protected]>
> On 2 Jun 2026, at 17:33, Wes Hardaker <[email protected]> wrote:
> 
> Roy Arends <[email protected]> writes:
> 
>> LocalRoot needs scaling and provisioning in different ways than RSS
>> scaling.
> 
> Yes, and that's a bit harder to capture and likely agree upon. My
> experience of running the localroot.isi.edu service shows that it's not
> hard to get working (as no one has said "it didn't work for me").  But
> I'm not sure we'll all agree on the right balance there.  Anything that
> requires more configuration *is* harder, but it's unclear whether it
> actually means it's actually also easier because it works better since
> you're never disconnected from the data.

I agree, though the technical aspects are trivial. A minimal config to get the root zone from $somewhere, plus some checking for integrity and freshness. The technology exists and has been deployed today.

The coordination of $somewhere is the harder part.

Warmly,

Roy


_______________________________________________
DNSOP mailing list -- [email protected]
To unsubscribe send an email to [email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.