[dns-operations] DNS trust dependencies for TLDs

Antoin Verschuren Antoin.Verschuren at sidn.nl
Mon Jun 15 09:20:10 UTC 2009


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

> -----Original Message-----
> From: Matthew Dempsky [mailto:matthew at dempsky.org]
> Subject: Re: [dns-operations] DNS trust dependencies for TLDs
> 
> Can you elaborate on what kind of glue failures and operation errors
> you're concerned about?  E.g., if you don't trust the root servers to
> serve A records correctly, how do you trust them to serve NS records
> correctly?

What would happen if we accidentally deleted all *.nic.nl A records from our nic.nl zone ?
(and/or from the .nl zone...)

I would say no authoritative answer for .nl would exist anymore on the *.nic.nl nameservers, but the out of bailiwick nameservers would still produce valid answers for the .nl zone, and there is no way we could cause their glue to change, either in their zones, or at the root.

Antoin Verschuren

Technical Policy Advisor
SIDN
Utrechtseweg 310
PO Box 5022
6802 EA Arnhem
The Netherlands

T +31 26 3525500
F +31 26 3525505
M +31 6 23368970
E antoin.verschuren at sidn.nl
W http://www.sidn.nl/

-----BEGIN PGP SIGNATURE-----
Version: 9.6.3 (Build 3017)

wsBVAwUBSjYSSjqHrM883AgnAQjkuAgAmWoqOXeYntqcMgOGub/xtjE/qv/uVKez
6EYhYtI7hoLr2T6qo3+oq9ewO904s1RlJjmneyYLAfZV3lWTGj8azDqFENTZjjwl
08N7XmQXBKEdwt5X8brMQLJBlC/dPkaLLJldbi8bg05jiQvs4SOEwi5DPba7KVov
raL8TKn7JAwpLfGcj6kW0zcZG35EXBi0tWmPBLWERxy03AiQ1pzs1Y5eEOghOC/V
/gqCX9owZ+w8TG2cSLpNBbRdgtNxeHzq6qN6Rhg5YLTlH/wh1LIa5pf0zpALRzGd
/BZzlF/pmKTv0UmzW2A9JJCpsOBQGecosTIjJcnanOhKDhE5rCbZOg==
=JA1l
-----END PGP SIGNATURE-----



More information about the dns-operations mailing list