LWN.net Logo

Certificates and "authorities"

Certificates and "authorities"

Posted Sep 9, 2011 0:07 UTC (Fri) by mtaht (✭ supporter ✭, #11087)
In reply to: Certificates and "authorities" by tialaramex
Parent article: Certificates and "authorities"

Getting your dns signed with dnssec has become easier and easier with the more current versions of bind.

In fact, both bufferbloat.net (running on a x86_64 box) and http://jupiter.lab.bufferbloat.net (running on a mips based cerowrt box) are now both signed, and the overhead seems non-existent.

comcast is running a set of dnssec enabled dns servers now, as well, which work great as forwarders.

dns.comcast.net

There is a tool for firefox that can validate if your dns signed, here:

https://addons.mozilla.org/en-US/firefox/addon/dnssec-val...

Perhaps one day this could be more effective than CAs.


(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds