RE: [dns-wg] RIPE NCC DNSSEC on the reverse tree update.
-
To: "Brett Carr" <>
-
From: Randy Bush <>
-
Date: Mon, 28 Nov 2005 06:01:50 -1000
> We saw some zone file corruption during the early hours of the
> morning, this caused a failsafe operation to takeover and hence
> the zones were published without signatures.
considering the obvious attack paths this opens, one assumes that
this 'failsafe' would not be part of the operation of a secure
zone in normal, as opposed to trial, operation.
randy
|