[DNSOP] Re: QName Minimization vs Aggressive NSEC vs Encrypt ed and Authenticated DNS vs Serve Stale vs DNSSEC vs LocalRoot
Roy Arends <[email protected]>
| Newsgroups | gmane.ietf.dnsop |
|---|---|
| Message-ID | <[email protected]> |
> On 2 Jun 2026, at 17:33, Wes Hardaker <[email protected]> wrote: > > Roy Arends <[email protected]> writes: > >> LocalRoot needs scaling and provisioning in different ways than RSS >> scaling. > > Yes, and that's a bit harder to capture and likely agree upon. My > experience of running the localroot.isi.edu service shows that it's not > hard to get working (as no one has said "it didn't work for me"). But > I'm not sure we'll all agree on the right balance there. Anything that > requires more configuration *is* harder, but it's unclear whether it > actually means it's actually also easier because it works better since > you're never disconnected from the data. I agree, though the technical aspects are trivial. A minimal config to get the root zone from $somewhere, plus some checking for integrity and freshness. The technology exists and has been deployed today. The coordination of $somewhere is the harder part. Warmly, Roy _______________________________________________ DNSOP mailing list -- [email protected] To unsubscribe send an email to [email protected]