Re: [dnsext] stub validation

Paul Vixie <vixie@isc.org> Mon, 25 October 2010 01:38 UTC

Return-Path: <owner-namedroppers@ops.ietf.org>
X-Original-To: ietfarch-dnsext-archive@core3.amsl.com
Delivered-To: ietfarch-dnsext-archive@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id 6FCD23A67FA; Sun, 24 Oct 2010 18:38:12 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.837
X-Spam-Level:
X-Spam-Status: No, score=-1.837 tagged_above=-999 required=5 tests=[AWL=-0.530, BAYES_00=-2.599, MISSING_HEADERS=1.292]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id lMsJqKYz5oar; Sun, 24 Oct 2010 18:38:11 -0700 (PDT)
Received: from psg.com (psg.com [IPv6:2001:418:1::62]) by core3.amsl.com (Postfix) with ESMTP id 944DB3A677D; Sun, 24 Oct 2010 18:38:11 -0700 (PDT)
Received: from majordom by psg.com with local (Exim 4.72 (FreeBSD)) (envelope-from <owner-namedroppers@ops.ietf.org>) id 1PABya-000Chb-9y for namedroppers-data0@psg.com; Mon, 25 Oct 2010 01:35:52 +0000
Received: from [2001:4f8:3:bb:230:48ff:fe5a:2f38] (helo=nsa.vix.com) by psg.com with esmtps (TLSv1:CAMELLIA256-SHA:256) (Exim 4.72 (FreeBSD)) (envelope-from <vixie@vix.com>) id 1PAByY-000ChN-79 for namedroppers@ops.ietf.org; Mon, 25 Oct 2010 01:35:50 +0000
Received: from nsa.vix.com (localhost [127.0.0.1]) by nsa.vix.com (Postfix) with ESMTP id F2A2FA1043 for <namedroppers@ops.ietf.org>; Mon, 25 Oct 2010 01:35:49 +0000 (UTC) (envelope-from vixie@nsa.vix.com)
From: Paul Vixie <vixie@isc.org>
cc: "namedroppers@ops.ietf.org" <namedroppers@ops.ietf.org>
Subject: Re: [dnsext] stub validation
In-Reply-To: Your message of "Mon, 25 Oct 2010 01:24:01 GMT." <88612.1287969841@nsa.vix.com>
References: <C8EA875A.83BA%roy@nominet.org.uk> <8D01F5E3-F863-4873-BB0E-654FA89983F7@virtualized.org> <88612.1287969841@nsa.vix.com>
X-Mailer: MH-E 8.1; nil; GNU Emacs 23.1.1
Date: Mon, 25 Oct 2010 01:35:49 +0000
Message-ID: <89335.1287970549@nsa.vix.com>
Sender: owner-namedroppers@ops.ietf.org
Precedence: bulk
List-ID: <namedroppers.ops.ietf.org>
List-Unsubscribe: To unsubscribe send a message to namedroppers-request@ops.ietf.org with
List-Unsubscribe: the word 'unsubscribe' in a single line as the message text body.
List-Archive: <http://ops.ietf.org/lists/namedroppers/>

> From: Paul Vixie <vixie@isc.org>
> Date: Mon, 25 Oct 2010 01:24:01 +0000
> 
> ...at the risk of being that guy who just won't shut up about something,
> let me say that until DNSSEC is commonplace, DNSSEC is a failure.  when
> every apple and microsoft and google and RIM platform including every
> mobile phone can either validate end-to-end based on trust anchors (using
> DNSSEC), or validate hop-by-hop based on transaction signatures (using
> TSIG) from a trusted (and reachable!) rdns, then DNSSEC won't have been
> worth its (considerable) engineering cost.

s/won't/will/, sorry.