Comment 2 for bug 2027797

Revision history for this message
Seth Arnold (seth-arnold) wrote :

Thanks for the report; it's my understanding that "real" DNSSEC deployments at sites that care will do all the DNSSEC enforcement with a local recursor because the application APIs are immature / underspecified / etc.

Such centralization also makes it far easier for the DNS operations team to work around misconfigured DNSSEC systems in the wild by setting Negative Trust Anchors on portions of the DNS tree (as described at https://doc.powerdns.com/recursor/dnssec.html#negative-trust-anchors ) when necessary.

Thanks