11 Jun
2019
11 Jun
'19
9 a.m.
On 10 Jun 2019, at 18.04, Shane Kerr <shane@time-travellers.org> wrote:
Of course, if the goal was ADDING of DS records, then I admit that the system is not there. I can see the benefit of being able to add DS records to the parent via CDS/CDNSKEY, especially for operators trying to secure (for example) reverse DNS for lots of /24's.
Is this important to you (or anyone else)?
I’ll raise my hand here. We hold a legacy PI /24, which means the parent, in the DNS sense, is run by a 3rd party, not us nor RIPE. Of course that 3rd party does not support DNSSEC, at least last time I asked. Med venlig hilsen / Best regards Erwin Lansing Head of Security & Chief Technologist