Re: Magic for NSEC3

2009-01-07 Thread B C
On Mon, Jan 5, 2009 at 5:57 PM, Jim k0...@arrl.net wrote: While testing our DNSSEC signing product, I found that the expense of signing with NSEC3 versus NSEC was very data dependent. In TLD type zones with a sparse number of records that needed to be signed, signing time could be reduced

Re: Magic for NSEC3

2009-01-03 Thread Mark Andrews
In message fa2e1350901031122w75768929h3b17e0a47b806...@mail.gmail.com, Jonathan Petersson writes: Hi all, Hopefully this post wont cause as much SPAM as my last one. About a year ago I started looking into DNSSEC and how to work with it for dynamic updates etc. Since only NSEC was

Re: Magic for NSEC3

2009-01-03 Thread Jonathan Petersson
Thanks for your input /Jonathan On Jan 3, 2009, at 16:13, Mark Andrews mark_andr...@isc.org wrote: In message fa2e1350901031122w75768929h3b17e0a47b806...@mail.gmail.com, Jonathan Petersson writes: Hi all, Hopefully this post wont cause as much SPAM as my last one. About a year ago I