3 ms·
needs more RRSIG - I don't understand why you'd launch a new DNS product at this point without DNSSEC support.
by trotsky 16y ago
needs more RRSIG - I don't understand why you'd launch a new DNS product at this point without DNSSEC support.
- mike-cardwell 16y agoWhich record types does it support?
- mike-cardwell 16y agoAh, it's on their FAQ page - http://aws.amazon.com/route53/faqs/ http://aws.amazon.com/route53/faqs/ They support A, AAAA, CNAME, MX, NS, PTR, SOA, SPF, SRV, TXT, which is better than most. But I agree, why on Earth would they not support the DNSSEC record types? It's not as if it would have been any extra work for them...
- smountcastle 16y agoThey're probably using an open source authoritative DNS server which doesn't yet support DNSSEC. If they upgrade to BIND 9.7 or NSD they'll get DNSSEC support for free.
- jgreen10 16y agobecause like... the whole world uses DNSSEC right?
- mike-cardwell 16y agoWhat is your point? A significant number of people don't use DNSSEC because they're tied to DNS services which don't support it. And that is an argument for creating more services without support for it?
- jgreen10 16y agoI imagine the argument is that it's harder and they need time and it's not a critical component so it's better to bootstrap their business first. You know, entrepreneurship.
- mike-cardwell 16y agoI don't buy it. They provide support for the "SPF" record type, but not "RRSIG". They would be equally simple to implement, yet DNSSEC would be hugely more beneficial. I've never come across anyone using the SPF record type. nearly everyone just uses TXT for that. I think DNSSEC was just an oversight on Amazons behalf. A mistake that they will hopefully fix in the not too distant future.