[dns-operations] DNSSEC deployment incentives

Mal malz at jetlan.com
Tue Jun 18 11:53:46 UTC 2019

On 18/06/2019 7:46 pm, Bill Woodcock wrote:
> When I authenticate to my server, I’d prefer it to actually be my server. 
>                 -Bill

Why not get some TLSA records going for that server too Bill, if you're
using TLS?  Postfix plays real nice with DNSSEC & DANE.

Jim will need to continue his trust of those unsigned IPv6 DNS records
and hope that he's actually talking to his favorite box.  He'll never
truly know though.


More information about the dns-operations mailing list