← Back to context

Comment by tptacek

3 hours ago

It's explicitly not the point of DNSSEC, which has for most of its entire existence been designed to be run as a server-to-server protocol, with stub resolvers trusting their upstream DNS servers.

I agree with you, though. It's utterly pointless.

Not true, RFC4035 says all security aware resolvers SHOULD verify the signatures. It's far from pointless when actually implemented. Don't dismiss a whole protocol just because some historical implementations have been half assed.

  • The RFC uses "security-aware" to set them apart from ordinary resolvers, which are what every mainstream resolver uses.