-
-
Notifications
You must be signed in to change notification settings - Fork 129
Open
Labels
Description
Investigate signing our zones with DNSSEC. This allows authenticity checks from the root zone down to our zone contents, by transitively verifying signatures.
This would prevent third-parties from tampering with our DNS records for resolvers that validate DNSSEC.
The risk is that mishandling DNSSEC can cause the zone to become unavailable until DNSSEC is fixed or TTLs expire.
Small survey among popular distros
- alpinelinux.org
- archlinux.org
- debian.org
- fedoraproject.org
- freebsd.org
- gentoo.org
- opensuse.org
- ubuntu.com
emilylange and joshbukervcunat and infinisil