Re: NSD and DNSSEC signature refreshing and ZSK rotation

"Michael A. Peters" <[email protected]>
Newsgroups gmane.network.dns.nsd.general
Message-ID <[email protected]>
On 02/15/2018 09:26 AM, Paul Wouters wrote:
>
>> On Feb 15, 2018, at 12:23, Michael A. Peters <[email protected]> wrote:
>
>
>
>> ZSK is easy but ZSK should be 1024-bit to keep DNS responses small,
>
> There is no proof this is needed or required.
>
> And strong reasons to not use 1024 RSA anymore. The root ZSK is now 2048 with no issues reported.
>
> Paul
>

Thank you.

I believe the fear was abuse in DDoS amplification attacks.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.