On 28 April 2016 at 06:37, Edward Lewis <edward.le...@icann.org> wrote:

>
> Not sure if that answers the question fully.  Hope it helps.
>

It helps, for sure.  So if I understand you correctly, at the TLD level
it's 4:1 in favour of NSEC3, and all of those are opt-out.
I imagine that will change as the number of DS records rise, but it gives
us an idea of the scale of the issue.

So back to Shane's question which I was responding to ...
We can't say that most zones are NSEC or NSEC3, but we can say there are an
awful lot of TLDs that are NSEC3 opt-out.

If someone can get me a relatively current, and relatively complete, set of
TLD zones, I could volunteer to check the next level down.  I don't think I
have time to go through the process of signing and faxing all those zone
file access agreements though.
_______________________________________________
DNSOP mailing list
DNSOP@ietf.org
https://www.ietf.org/mailman/listinfo/dnsop

Reply via email to