Re: How do we get the whole world to upgrade to DNSSEC capable resolvers?

Joe Abley <jabley@ca.afilias.info> Fri, 25 July 2008 23:56 UTC

Return-Path: <owner-namedroppers@ops.ietf.org>
X-Original-To: ietfarch-dnsext-archive@core3.amsl.com
Delivered-To: ietfarch-dnsext-archive@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id 2DA723A68D6; Fri, 25 Jul 2008 16:56:59 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.048
X-Spam-Level:
X-Spam-Status: No, score=-1.048 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, FH_RELAY_NODNS=1.451, RDNS_NONE=0.1]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id hAxX8t4q6J8y; Fri, 25 Jul 2008 16:56:58 -0700 (PDT)
Received: from psg.com (psg.com [IPv6:2001:418:1::62]) by core3.amsl.com (Postfix) with ESMTP id 3DD483A67D4; Fri, 25 Jul 2008 16:56:57 -0700 (PDT)
Received: from majordom by psg.com with local (Exim 4.69 (FreeBSD)) (envelope-from <owner-namedroppers@ops.ietf.org>) id 1KMX26-000JQv-Es for namedroppers-data@psg.com; Fri, 25 Jul 2008 23:49:10 +0000
Received: from [199.212.90.4] (helo=monster.hopcount.ca) by psg.com with esmtps (TLSv1:AES256-SHA:256) (Exim 4.69 (FreeBSD)) (envelope-from <jabley@ca.afilias.info>) id 1KMX22-000JQP-5C for namedroppers@ops.ietf.org; Fri, 25 Jul 2008 23:49:08 +0000
DomainKey-Signature: a=rsa-sha1; q=dns; c=nofws; s=monster; d=ca.afilias.info; h=Received:Cc:Message-Id:From:To:In-Reply-To:Content-Type:Content-Transfer-Encoding:Mime-Version:Subject:Date:References:X-Mailer; b=f+M0AL4k6+jHcnZQ+2uTnhHEFu7bi4LB5I+JucX8J8csRs2Es5KAprNemXRZp42txIzGJ7K6UFsVUihsE1nJC9WzTnPC+F2OBGR8FNYuHpHqE/CpeFwrdtTgaF+AYvhT;
Received: from [209.226.201.250] (helo=[10.205.40.104]) by monster.hopcount.ca with esmtpsa (TLSv1:AES128-SHA:128) (Exim 4.69 (FreeBSD)) (envelope-from <jabley@ca.afilias.info>) id 1KMX0Y-000BP4-Fp; Fri, 25 Jul 2008 23:47:34 +0000
Cc: Andrew Sullivan <ajs@commandprompt.com>, namedroppers@ops.ietf.org
Message-Id: <872FAAA4-94ED-4CE8-BA8D-7792BEE2D867@ca.afilias.info>
From: Joe Abley <jabley@ca.afilias.info>
To: Jelte Jansen <jelte@NLnetLabs.nl>
In-Reply-To: <488A5CC8.7010009@NLnetLabs.nl>
Content-Type: text/plain; charset="US-ASCII"; format="flowed"; delsp="yes"
Content-Transfer-Encoding: 7bit
Mime-Version: 1.0 (Apple Message framework v926)
Subject: Re: How do we get the whole world to upgrade to DNSSEC capable resolvers?
Date: Fri, 25 Jul 2008 19:47:39 -0400
References: <2FFE6519-7E9C-4DE8-AF69-697A4D875011@nominum.com> <20080723191636.GB32507@outpost.ds9a.nl> <8A91CF57-0CBD-4CF2-BF59-C7D59CB4B7B9@virtualized.org> <20080724060743.GA7420@outpost.ds9a.nl> <48886C4D.4020500@ca.afilias.info> <63C0FFE7-17E6-4ECE-9A12-0537FE2E3F4B@ca.afilias.info> <4888FED2.6060204@NLnetLabs.nl> <E7388E94-D031-4059-91F9-1596A254E21C@ca.afilias.info> <20080725193101.GB8193@outpost.ds9a.nl> <BEADC795-3C76-407A-A979-2B0AAACE0328@ca.afilias.info> <20080725221002.GK29775@commandprompt.com> <488A5CC8.7010009@NLnetLabs.nl>
X-Mailer: Apple Mail (2.926)
Sender: owner-namedroppers@ops.ietf.org
Precedence: bulk
List-ID: <namedroppers.ops.ietf.org>

On 25 Jul 2008, at 19:07, Jelte Jansen wrote:

> Exactly, if you cannot trust your resolver, or the so-called last  
> mile,
> you need to do your own verification, and for that you need to  
> configure
> your trust anchors, be it a set for a signed root, DLV, or plain  
> manually.

Got it.


Joe


--
to unsubscribe send a message to namedroppers-request@ops.ietf.org with
the word 'unsubscribe' in a single line as the message text body.
archive: <http://ops.ietf.org/lists/namedroppers/>