In article <8e5d5d6c-6893-473d-a2fe-dcb0b46e7...@dukhovni.org> you write:
>Some of the more subtle, but still very important failure modes
>are not obvious unless *tested*.  It is would be a disservice to
>the ecosystem to blindly turn on only partly working DNSSEC which
>is actually broken in important ways.

I think it's a swell idea to offer people DNSSEC testing services but
it's hopeless to conflate it with key rotation.

R's,
John

_______________________________________________
DNSOP mailing list
DNSOP@ietf.org
https://www.ietf.org/mailman/listinfo/dnsop

Reply via email to