On 3/31/20 6:47 AM, Brian Somers wrote: > One useful thing I could say (If you haven’t hit delete yet) is that I *HAVE* > seen RRSIGs with compressed signers in the wild, so never assume that, just > because RFCs say MUST NOT, you’ll never see these horrible things.
Sure, validators MUST NOT crash on those, etc... but does that mean they SHOULD accept such signatures? I don't think so. (unless there's some additional motivation) --Vladimir _______________________________________________ dns-operations mailing list [email protected] https://lists.dns-oarc.net/mailman/listinfo/dns-operations
