In article <8e5d5d6c-6893-473d-a2fe-dcb0b46e7...@dukhovni.org> you write: >Some of the more subtle, but still very important failure modes >are not obvious unless *tested*. It is would be a disservice to >the ecosystem to blindly turn on only partly working DNSSEC which >is actually broken in important ways.
I think it's a swell idea to offer people DNSSEC testing services but it's hopeless to conflate it with key rotation. R's, John _______________________________________________ DNSOP mailing list DNSOP@ietf.org https://www.ietf.org/mailman/listinfo/dnsop