Verisign brain damage and DNSSec.....Was:Re: What *are* they smoking?

Eric Germann ekgermann at cctec.com
Tue Sep 16 22:10:34 UTC 2003


Re: Verisign brain damage and DNSSec.....Was:Re: What *are* they smoking?And
whats to say they don't get around our methods of blacklisting it by
changing the IP around every zone update?

  -----Original Message-----
  From: owner-nanog at merit.edu [mailto:owner-nanog at merit.edu]On Behalf Of
Valdis.Kletnieks at vt.edu
  Sent: Tuesday, September 16, 2003 2:18 PM
  To: bmanning at karoshi.com
  Cc: bownes at web9.com; gmaxwell at martin.fl.us; haesu at towardex.com;
marius at marius.org; nanog at merit.edu
  Subject: Re: Verisign brain damage and DNSSec.....Was:Re: What *are* they
smoking?


  On Tue, 16 Sep 2003 11:08:11 PDT, bmanning at karoshi.com said:
  > > On Tue, 16 Sep 2003 09:59:40 PDT, bmanning at karoshi.com said:

  >       thats one aspect yes.  the valdiation chain should tell
  >       you who signed the delegations.  It won't lie.
  >       you will know that V'sign put that data there.

  How frikking many hacks will we need to BIND9 to work around this
braindamage?
  One to stuff back in the NXDomain if the A record points there, another to
  do something with make-believe DNSsec from them..... What's next?
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://mailman.nanog.org/pipermail/nanog/attachments/20030916/eb537e64/attachment.html>


More information about the NANOG mailing list