DNSSEC Best Practices

Mark Tinka mark at tinka.africa
Wed Apr 28 10:02:18 UTC 2021


On 4/28/21 11:51, Tony Finch wrote:

> Yes. I recommend p256 because the security advantages of p384 are not
> significant enough to justify the increased costs in space (packet size)
> and time.

Both 13 and 14 are already smaller than 8 (which is the most widely 
deployed algorithm today).

512 bits vs 768 bits is not going to break the Internet.

Mark.


More information about the NANOG mailing list