Comment by ekr____
4 hours ago
It's actually not safe for clients to perform local validation because a quite significant fraction of middleboxes and the like strip out RRSIG and the like or otherwise tamper with the records in such a way that the signatures don't validate.
No comments yet
Contribute on Hacker News ↗