RFC 9102: "TLS DNSSEC Chain Extension", finally published as "experimental" -- a few years after a long, acrimonious battle in the IETF TLS WG to get it published as "standards track" failed: rfc-editor.org/rfc/rfc9102.h…
Shumon Huque covers much ground in his presentation, including a call for an ICANN role for DNS providers, and handling parental detection of CDS/CDNSKEY records - on which there were new ideas proposed by Johan Stenstam during IDS yesterday.
#OARC41#LoveDNS ^CA
Shumon Huque from Salesforce presenting "Automation of DNSSEC provisioning and maintenance" asserts that robust automation in these areas should make it easier to deploy DNSSEC
indico.dns-oarc.net/event/47…#OARC41#LoveDNS ^CA
"“.. clash of E.U. privacy law and U.S. surveillance law. As the E.U. will not change its fundamental rights to please the NSA, the only way to overcome this clash is for the U.S. to introduce solid privacy rights for all people — including foreigners"
washingtonpost.com/world/eur…
I'm speaking at @NS1's INS1GHTS2020 conference today, at 2:40PM UTC on DNSSEC with Multiple Providers: ins1ghts.ns1.com/ . You might win an Oculus Quest if you attend ..