[Dnssec-deployment] Root Zone DNSSEC Deployment Technical Status Update

Paul Vixie vixie at isc.org
Fri Jul 16 23:03:35 EDT 2010


> From: Russ Mundy <mundy at sparta.com>
> Date: Fri, 16 Jul 2010 19:02:03 -0400
> 
> ... Many people said that this event would never happen but now the root
> zone is signed!!

whenever i made a sucker bet with somebody about the root not getting
signed i put a timelimit on it.  i once bet steve $20 it wouldn't be signed
by january 1 of some year that seemed futuristic at the time, so i took his
money like it had wings.  most people wouldn't take the bet.  the trick was
to never say never, 'cuz i knew i'd end up paying off somehow someday.

> It was very rewarding to see such an important event be accomplished
> with such professionalism that most of the "Internet world" not even
> realizing that the root signing had occurred - that is, itself, a
> great accomplishment.

indeed.  and let's give credit where due -- because there are still no
external applications that add value in the face of this metadata, the
biggest reason we finally have a signed root and growing cadre of signed
tld's and sld's is because of... dan kaminsky's bug.


More information about the Dnssec-deployment mailing list