.gov support of DNSSEC
"Jason Frisvold" <[email protected]>
| Newsgroups | gmane.network.djbdns |
|---|---|
| Message-ID | <[email protected]> |
Hi all, I guess I've been meaning to join this list for some time, but since DJBDNS just seems to work, I haven't had a real need... However, that may change. It appears that the Federal Government has mandated a rollout of DNSSEC for all .gov domains. They're spinning this as a way to be "sure" that you get to the proper government site, but fail to mention that without valid resolvers on the user end, there is still zero security. Regardless, this may mean that DNSSEC is here to stay. It's still a bit early, though, and the apparent mandate for IPv6 hasn't proven to make it any more popular either. What is being done on the DJBDNS front, though? I see mention of a new crypto DNS library, DNSCurve, though it appears that there is no current release. Is this the answer to DNSSEC? Will this be "compatible" with DNSSEC, or will I eventually be forced to move to other resolvers? Thanks! -- Jason 'XenoPhage' Frisvold [email protected] http://blog.godshell.com