AW: AW: AW: Specifying NSEC3 salt with dnssec-policy

2024-10-01 Thread Klaus Darilion via bind-users
Hi Petr! > It can be said that the interface pushes people to follow RFC 9276, i.e. > no salt and no extra iterations. > > It is an pointless exercise which only makes servers easier to DoS for > no benefit. I understand your decision to push people towards RFC 9276. > Why do you need extra sal

Re: AW: AW: AW: Specifying NSEC3 salt with dnssec-policy

2024-10-01 Thread Petr Špaček
On 01. 10. 24 15:41, Klaus Darilion wrote: Hi Petr! It can be said that the interface pushes people to follow RFC 9276, i.e. no salt and no extra iterations. It is an pointless exercise which only makes servers easier to DoS for no benefit. I understand your decision to push people towards R