In article <[EMAIL PROTECTED]> you write:
>* marcus sachs:
>
>> While we wait for applications to become DNSSEC-aware,
>
>Uhm, applications shouldn't be DNSSEC-aware.  Down that road lies
>madness.  What should an end user do when the browser tells him,
>"Warning: Could not validate DNSSEC signature on www.example.com,
>signature has expired.  Continue to connect?"

        The application just rejects the answer.  Trys again a
        couple of times then reports failure.  This is no different
        to the application talking to the validating resolver a
        couple of time and then reporting failure.

        The advantage of having the application do it is that you
        don't need to secure the connection between the validating
        resolver and the application.

        Mark

Reply via email to