13 Feb
2007
13 Feb
'07
6:27 p.m.
On Feb 13, 2007, at 17:04, Randy Bush wrote:
DNSSEC deployment has to start somewhere.
the root or it will not scale
True. But what should the DNS engineers do while the layer-9 issues about the root key rumble on and on? I very much doubt anyone's going to take responsibility for signing the root unless they know that, yes DNSSEC really does work and won't break the internet. The only way of establishing that IMO is "real world" experience outside the research environment where DNSSEC deployment has been done to date.