1 Mar 2009 14:32
Re: [dnssec-deployment] [dnsext] Sidestepping the root
Ben Laurie <ben <at> links.org>
2009-03-01 13:32:40 GMT
2009-03-01 13:32:40 GMT
Paul Vixie wrote: > On 21.02.2009, at 18:11, Ben Laurie wrote: >> So here's an idea: why don't the TLDs who have deployed or are willing to >> deploy DNSSEC get together and each run a DLV zone for all the others? > > candidly, it's because of the trust problem. ISC operates a DLV registry > and it has a few TLDs in it (more now that we've imported IANA's ITAR) but > the TLD operators are terribly concerned about kingmaking and not even ISC > is trustworthy enough to make that concern go away. truthfully: *noone* is. Who would be king in the system I describe? > i understood this better after the man from .RU shook his fist at the room > down in atlanta, apparently the idea of russia depending on the united > states (which is how the world sees ICANN) to authenticate their own names > to their own users flies in the face of national sovereignty. In the system I describe, .ru would authenticate their own names to their own users. -- -- http://www.apache-ssl.org/ben.html http://www.links.org/ "There is no limit to what a man can do or how far he can go if he doesn't mind who gets the credit." - Robert Woodruff -- to unsubscribe send a message to namedroppers-request <at> ops.ietf.org with the word 'unsubscribe' in a single line as the message text body. archive: <http://ops.ietf.org/lists/namedroppers/>(Continue reading)
RSS Feed