[dnssec-deployment] split-view DNSSEC Best Current Practices
Rob Austein
sra at isc.org
Wed Jan 12 13:19:41 EST 2005
At Wed, 12 Jan 2005 12:15:06 -0500, Steve Crocker wrote:
>
> I look forward to reading this. I was thinking about split views a
> couple of days ago and I was thinking it would be very helpful to have a
> document that shows how to deploy DNSSEC in such environments, so I'm
> very pleased to see this. I see your advice is DON'T. I fear this
> won't be enough, and I will read your document eagerly.
what steve said. except that in my case i don't just fear that
"DON'T" won't suffice, i'm certain of it. we're stuck with split-dns
as long as we have firewalls, and i don't see firewalls going away.
borrowing an observation from john klensin, "i will share your
optimism when large flocks of pigs are reliably reported to be flying
over redmond."
the above notwithstanding, i too look forward to reading the draft.
More information about the Dnssec-deployment
mailing list