Jan,
we sign everything with NSEC3 but that is our local policy I think
it makes more sense for the default to be NSEC but with the change to
be easy.
Brett
On 9 June 2016 at 09:26, Jan Včelák <jan.vcelak(a)nic.cz> wrote:
Hello guys,
we are currently tuning the DNSSEC default parameters. And we haven't
settled on whether NSEC or NSEC3 should be used for authenticated
denial. Tough decision...
We would appreciate any comments from your point of view. :-)
Jan
_______________________________________________
knot-dns-users mailing list
knot-dns-users(a)lists.nic.cz
https://lists.nic.cz/cgi-bin/mailman/listinfo/knot-dns-users
--
Brett