[dns-operations] Data about load increase on *resolvers* when enabling DNSSEC validation?

Stephane Bortzmeyer bortzmeyer at nic.fr
Sun Sep 9 16:54:28 UTC 2012

There are many published papers about the load created by DNSSEC on
authoritative name servers. And a lot of practical experience as well,
some of it publically documented.

For the validating *resolvers*, I find on the Web a few tests in a lab
environment (setting up BIND or Unbound with and without validation,
and launching many DNS requests at them and measuring the differences)
but I do not find data about *actual* deployments, for instance an ISP
publishing the results of enabling validation ("We observed no
difference" or "We had to triple the number of boxes used as resolvers
because of the increased CPU load"). Any pointer?

