-
-
Notifications
You must be signed in to change notification settings - Fork 132
DNSSEC signing #878
Copy link
Copy link
Open
Labels
Description
Investigate signing our zones with DNSSEC. This allows authenticity checks from the root zone down to our zone contents, by transitively verifying signatures.
This would prevent third-parties from tampering with our DNS records for resolvers that validate DNSSEC.
The risk is that mishandling DNSSEC can cause the zone to become unavailable until DNSSEC is fixed or TTLs expire.
Small survey among popular distros
- alpinelinux.org
- archlinux.org
- debian.org
- fedoraproject.org
- freebsd.org
- gentoo.org
- opensuse.org
- ubuntu.com
Reactions are currently unavailable