Mukund Sivaraman wrote:
On Tue, Aug 15, 2017 at 11:29:56PM -0700, Paul Vixie wrote:
we should give up.

or we shouldn't.

not a mixture.

I'm not saying we should give up.. but it's going to be a while before
we get to an utopia of maximal DNSSEC deployment. In the meantime, there
are practical problems that need mitigation.

anybody who needs secure denial of existence, of wildcards or other data, should deploy dnssec.

anybody who needs their networking partners to have this, should urge their partners to deploy dnssec.

if we don't believe that this can be done, then we should give up on dnssec.

there is no middle road here.

--
P Vixie

_______________________________________________
DNSOP mailing list
DNSOP@ietf.org
https://www.ietf.org/mailman/listinfo/dnsop

Reply via email to