[dns-wg] Announcement: Test Report on DNSSEC impact on SOHO CPE (fwd)

Paul Wouters paul at xelerance.com
Tue Sep 16 13:21:06 EDT 2008

---------- Forwarded message ----------
Date: Mon, 15 Sep 2008 15:40:10 +0100
From: Ray.Bellis at nominet.org.uk
To: RIPE DNS WG <dns-wg at ripe.net>
Subject: [dns-wg] Announcement: Test Report on DNSSEC impact on SOHO CPE

[with apologies for the cross-postings to multiple lists]

Dear Colleagues,

We would like to announce the publication of a joint study entitled
"DNSSEC Impact on Broadband Routers and Firewalls", available for
download at:


In summary (based on 24 tested units):

"... we conclude that just 6 units (25%) operate with full DNSSEC
  compatibility "out of the box."  9 units (37%) can be reconfigured to
  bypass DNS proxy incompatibilities.  Unfortunately, the rest (38%) lack
  reconfigurable DHCP DNS parameters, making it harder for LAN clients to
  bypass their interference with DNSSEC use.

  These findings, their potential impact on DNSSEC use by broadband
  consumers, and implications for router/firewall manufacturers, are
  presented and analyzed in this report. "

Ray Bellis
Senior Researcher in Advanced Projects
Nominet UK

Lisa A. Phifer
President, Core Competence, Inc.

More information about the Dnssec-deployment mailing list