[DNSOP] Re: DNSOPDELEXT: Proposed Delegation Type Ranges
Paul Wouters <[email protected]>
| Newsgroups | gmane.ietf.dnsop |
|---|---|
| Message-ID | <[email protected]> |
On Mon, 24 Aug 2026, Philip Homburg wrote: > A problem with DELEG is that if a nameserver that is not DELEG-aware serves > a DNSSEC signed zone with DELEG records then this will cause failures. > > So DELEXT is supposed to provide a solution to this problem for future > types (after DELEG), we cannot fix the current situation. We could decide DELEG is not the solution we were looking for, and look at a better redesign of DNS transport and child-parent information authentication and fold in native encryption and packet/signature sizes for PQ etc. It feels to me DELEG / DELEXT is adding a lot of complexity for what is ultimately a small use case (let DNS hosters update DNSSEC KSKs) to the point where perhaps a DNS v2.0 from scratch would be better. To me if feels the DELEG path is becoming more and more a stack of nifty hacks. Paul _______________________________________________ DNSOP mailing list -- [email protected] To unsubscribe send an email to [email protected]