Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Do I understand correctly: With DNSSEC the bar will be raised because the registrar of a specific domain will need to be compromised to change the DNS entries? So some misc country's CA that ends up trusted for whatever reason will not be able to sign records for another TLD?


Yep this is correct. See the note about "exclusion" on http://www.imperialviolet.org/2010/08/16/dnssectls.html




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: