[dns-operations] [Ext] Re: Evaluation of NSEC3-encloser attack

Edward Lewis edward.lewis at icann.org
Thu Apr 4 19:14:11 UTC 2024


On 3/27/24, 17:34, "dns-operations on behalf of Jim Reid" <dns-operations-bounces at dns-oarc.net on behalf of jim at rfc1035.com> wrote:

>IMO, there’s no added value in using NSEC3.

NSEC3 has opt-out, which is important for large, delegation-centric zones.  Noting, I'm no fan of NSEC3, but it does have that going for it.




More information about the dns-operations mailing list