[Dnssec-deployment] Curious about dnssec at the client level.

bert hubert bert.hubert at netherlabs.nl
Fri Dec 9 17:22:22 EST 2011

On Fri, Dec 09, 2011 at 04:39:25PM -0500, Robert Edmonds wrote:
> i wrote a validating stub resolver plugin for glibc:
>     https://github.com/edmonds/nss-ubdns
> it interfaces between the system's name service switch and libunbound so
> that validation occurs inside the process that calls gethostbyname(),
> getaddrinfo(), etc.  not sure if that counts as a "clever hack".

Hey, that is pretty cool! Do you always get the data you need to do full
validation just going through a resolver? 


More information about the Dnssec-deployment mailing list