[DNSOP] Re: Call for adoption: draft-huque-dnsop-multi-alg -rules-08 (Ends 2026-08-31)

Philip Homburg <[email protected]>
Newsgroups gmane.ietf.dnsop
Message-ID <[email protected]>
In your letter dated Sat, 15 Aug 2026 15:18:22 -0400 you wrote:
>And the first thing that happens is that one needs a few new things inside
>the VM, the absolute last patches to gcc 11 and openssl 1.1.1QAZT... and
>guess what... the DNS resolver libraries, or **localhost DNS-validator**
>inside are also old.   The VM won't be alive very long, and isn't exposed
>otherwise to the network...

If the VM is literally not exposed to the network, then I wonder why a 
validating resolver (or other DNSSEC validating software is included).

Note that an old VM will also have out of date root trust-anchors. Which
causes validation to fail unless to those files have been updated.

In any case, if the VM is running in a controlled environment, then there is
no need to worry. Nobody will sign with ECDSA in a controlled environment.

It only becomes a problem if the VM is in-fact connected to the internet
and one of the domains the VM tries to resolve is signed using different 
algorithms for the KSK and ZSK.

_______________________________________________
DNSOP mailing list -- [email protected]
To unsubscribe send an email to [email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.