On Tue, 6 Nov 2018, Benjamin Kaduk wrote:
I think I'm confused about what you mean by "the downgrade-resistance that DNSSEC gives automatically".
You cannot filter DNSSEC without the target being aware of being filtered (where filtering == downgrading) Paul _______________________________________________ TLS mailing list TLS@ietf.org https://www.ietf.org/mailman/listinfo/tls