On 28 April 2016 at 06:37, Edward Lewis <edward.le...@icann.org> wrote:
> > Not sure if that answers the question fully. Hope it helps. > It helps, for sure. So if I understand you correctly, at the TLD level it's 4:1 in favour of NSEC3, and all of those are opt-out. I imagine that will change as the number of DS records rise, but it gives us an idea of the scale of the issue. So back to Shane's question which I was responding to ... We can't say that most zones are NSEC or NSEC3, but we can say there are an awful lot of TLDs that are NSEC3 opt-out. If someone can get me a relatively current, and relatively complete, set of TLD zones, I could volunteer to check the next level down. I don't think I have time to go through the process of signing and faxing all those zone file access agreements though.
_______________________________________________ DNSOP mailing list DNSOP@ietf.org https://www.ietf.org/mailman/listinfo/dnsop