ietf
[Top] [All Lists]

Re: (short version) Re: Last Call: <draft-faltstrom-uri-10.txt> (The Uniform Resource Identifier (URI) DNS Resource Record) to Proposed Standard

2015-03-02 09:52:24
On Fri, Feb 27, 2015 at 01:39:47PM -0500, Sam Hartman wrote:

If you're willing to trust DNS and if you're using DNSSec, I don't see
why you can't just trust the target of the redirection.

That's what one generally does.  Indeed TLSA records don't change
that part of the picture when trust in DNSSEC anchors makes sense.

What are you getting out of forcing DANE?

I don't want to hijack this thread, so perhaps we can leave that
question for some future more appropriate context.

-- 
        Viktor.

<Prev in Thread] Current Thread [Next in Thread>