29 Aug
2005
29 Aug
'05
7:06 p.m.
Randy, you've confused me. What aspect of DNSSEC specifically "does not scale"? Do you mean having everyone embed trust anchors in their name server configurations for every signed TLD while we wait for the root to be signed?
yep
If so, I agree that's not scalable. But that's not what was under discussion here. At least I hope it wasn't.
no. you just want me to hold the trust keys for the zones you think are important. and, in today's email (for some value of 'today'), brett warns us that he has a handful of third level zones he thinks are important enough. hence "does not scale." randy