On Thu, 16 Jul 2009, Mark Andrews wrote:

The problem is not resolving portal.isp.com. The problem is that
mail.xelerance.com "resolves" to portal.isp.com, but never makes
it because my validating stub resolver has a DNSSEC key loaded
for xelerance.com. A problem that in the future will become worse
when the majority of the domains (and the root) is signed.

Paul

        Well if xelerance.com is signed then internal (split dns)
        representations also need to be signed.

I am not talking about internal. I am talking about a single DNSSEC
signed zone that becomes unreachable because I'm behind a hotspot.

this has nothing to do with split DNS and signing internal/eternal zones.

Paul
_______________________________________________
DNSOP mailing list
DNSOP@ietf.org
https://www.ietf.org/mailman/listinfo/dnsop

Reply via email to