Implementing DANE for qmail

Manvendra Bhangui <[email protected]> Sun, 9 Apr 2017 21:22:00 +0530
Newsgroups gmane.mail.qmail.general
Message-ID <CAOqj+1NaQy0t5xsvUXa6YP4xN4XT0CqTZ0=ckSPqsBUZ-=mkcg@mail.gmail.com>
I have been thinking about this and have followed this document

https://www.ietf.org/mail-archive/web/dane/current/pdfk2DbQF0Oxs.pdf

What I have understood is this

For Domain owners
publish a TLSA Resource Record (RR) and enforce your servers to use TLS.

For clients
query the TLSA RR and then decide to connect or not. This will require
modification to qmail-remote. As specified in the DANE protocol RFC,
the TLSA RR resulting from a DNS Query must be validated by DNSSEC. It
is MUST that the zone which has a TLSA RR must be signed by DNSSEC and
the applications which query the domain for TLSA RR validation should
use a DNSSEC aware resolver. This is where I am confused. Do all
resolver setup support DNSSEC?

Is there anyone working on this? If yes, how difficult would this be
to implement?

-- 
Regards Manvendra - http://www.indimail.org
GPG Pub Key
http://pgp.mit.edu:11371/pks/lookup?op=get&search=0xC7CBC760014D250C