[DNSOP] Re: DNS Security TXT - A standard for nominating sec urity contact points and policies via DNS TXT records
Paul Wouters <[email protected]>
| Newsgroups | gmane.ietf.dnsop |
|---|---|
| Message-ID | <[email protected]> |
After 5 clicks I still only see a raw md file - can you just publish this on datatracker and provide a link? Based on the first link, without DNSSEC you can’t trust the info, same if DNSSEC is broken. Not sure what’s gained beyond the SOA contact. And like security.txt files everywhere, it’s just outdated information on a web server that in itself cannot be trusted. So count me skeptical. A more secure approach is trying to context the entity with other out of band guarantees, like social media, whois or LinkedIn or various abuse groups. Paul > On Aug 6, 2026, at 11:59, Stephane Bortzmeyer <[email protected]> wrote: > > It does not seem there is an Internet-Draft for this but it may interest people here: > > Summary: > The report channel, published in DNS > > When people find security issues in Internet-facing systems, the > correct channel to report them isn't always clear, and the relevant > disclosure policy for the system isn't always apparent. DNS Security > TXT extends the work done by security.txt to answer this question > using DNS, arguably the most ubiquitous system on the Internet. > > When deployed, it gives security researchers, Internauts, and > concerned Internet citizens clear and authoritative direction to the > correct channels for reporting security issues, and to the policies an > organization sets out for all systems under a domain. > > https://dnssecuritytxt.org/ > > _______________________________________________ > DNSOP mailing list -- [email protected] > To unsubscribe send an email to [email protected] _______________________________________________ DNSOP mailing list -- [email protected] To unsubscribe send an email to [email protected]