Boston Linux & UNIX was originally founded in 1994 as part of The Boston Computer Society. We meet on the third Wednesday of each month, online, via Jitsi Meet.

BLU Discuss list archive


[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[Discuss] free SSL certs from the EFF



On 12/3/2014 10:52 AM, Derek Atkins wrote:
> Actually, it was designed to protect against that.  I sat in the
> IETF meetings where that was explicitly discussed.  If an intermediary
> strips the DNSSEC records out then a resolver expecting DNSSEC will
> force a validation error.

Which results in a denial of service for clients if DNSSEC is enforced. 
That's not protecting users; that's dumping them into black holes.


> Well, it sort of does, but it's not easy.  But this is why they use
> ZSKs.  The Root Zone KSK is mightily protected.

So, too, allegedly, were the keys at DigiNotar.

-- 
Rich P.



BLU is a member of BostonUserGroups
BLU is a member of BostonUserGroups
We also thank MIT for the use of their facilities.

Valid HTML 4.01! Valid CSS!



Boston Linux & Unix / webmaster@blu.org