[dns-operations] signing a zone with NSEC3 records.

bert hubert bert.hubert at netherlabs.nl
Thu Sep 10 13:52:23 UTC 2009

On Thu, Sep 10, 2009 at 3:40 PM, Ondřej Surý <ondrej.sury at nic.cz> wrote:
>> Which only helps if you have a delegation centric zone.  99.9999% of
>> zones are not delegation centric zones.
> You're right.  I'm bit TLD-centric :), since I guess the TLDs are mostly
> those who care about size of the zone.

I can tell you that the people hosting hundreds of thousands of zones
see this as a major issue, and in general, that DNSSEC is not on their
radar or roadmap at all.

So their silence should not be seen as an indication that there are no problems


More information about the dns-operations mailing list