nanog mailing list archives

Re: Verisign brain damage and DNSSec.....Was:Re: What *are* they smoking?


From: Valdis.Kletnieks () vt edu
Date: Tue, 16 Sep 2003 14:00:45 -0400

On Tue, 16 Sep 2003 09:59:40 PDT, bmanning () karoshi com said:
DNSsec will work properly with wildcards, regardless of where they are
in the DNS.

Which means that a rogue DNS can lead you down the garden path and
DNSsec won't give you a clue that you're being lied to.  It's the same
question as the "what happens to SSL to a phantom site?" - Verisign can
provide an A record for the server and an SSL cert that will work.

Attachment: _bin
Description:


Current thread: