Drawbacks of using DNSSEC
In practical terms, implementing DNSSEC can appear daunting. Best practices suggest periodic key rollovers, although they are not strictly necessary, and rollovers are known to be done incorrectly. Entire TLDs have screwed up their DNSSEC configurations, and thus gone dark to DNSSEC-aware resolvers, and this happens more often than you may suspect. It happens so often, in fact, that there is a website that tracks TLD outages due to errors in the DNSSEC configuration, and you might be surprised to see that these incidents include numerous government, military, and internet infrastructure domains.
Further, because a relatively small query can generate a much larger response, DNSSEC is also another favorite tool for ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access