Building consensus over DNSSEC enhancements to glibc.
Rich Felker
dalias@libc.org
Thu Nov 5 01:23:00 GMT 2015
On Wed, Nov 04, 2015 at 03:44:48PM -0500, Carlos O'Donell wrote:
> Community,
>
> I have written up a summary of the mailing list discussions
> surrounding DNSSEC and the enhancements required to better
> support it in glibc.
>
> https://sourceware.org/glibc/wiki/DNSSEC
>
> Any thoughts or comments would be much appreciated.
While I'm not opposed to clean ways to expose DNSSEC trust to
applications, I don't see a bit libc role in the ideal client setup:
you just run a local nameserver that verifies DNSSEC and replies with
ServFail upon receiving forged reslts/results that are supposed to be
signed but aren't.
Rich
More information about the Libc-alpha
mailing list