1 Sep 2009 01:49
Re: [dnsext] Working around proxies
Masataka Ohta <mohta <at> necom830.hpcl.titech.ac.jp>
2009-08-31 23:49:00 GMT
2009-08-31 23:49:00 GMT
Mark Andrews wrote: >>which is a lot more difficult than just >> >> support IPv6 >> >>even which is not happening. > Except it is. It's cruch time and residential ISP are now reacting. Well... According to some people, yes, IPv6 deployment has been happening for these 15 years. So? > There are commisioning CPE product development, now, to allow them > to support both IPv4 (NAT'd) and IPv6 into the future. It's easy to develop products. However, there is hardly any incentive for ISPs to replace all the CPEs, which costs a lot. Anyway, if we can instruct NAT vendors to follow our guideline on DNS relaying behavior, we can let them implement plain old DNS securely that there is no point to have DNSSEC, which is merely weakly secure.(Continue reading)
RSS Feed