4 ms·
I have to confess that I don't deeply understand DNSSEC. I've set it up on domains in AWS (Route53) and GCP (Cloud DNS) and found it pretty simple and never had
by thraxil 3y ago
I have to confess that I don't deeply understand DNSSEC. I've set it up on domains in AWS (Route53) and GCP (Cloud DNS) and found it pretty simple and never had any issues (only .com and .org, no weirder TLDs). Are all the problems that people complain about only relevant if you manage all the DNS infrastructure yourself (rather than just letting GCP/AWS handle the KSK, rotation, etc)? Or have I set up a ticking timebomb that's going to be a big outage at some point?
- agwa 3y agoYou should be fine as long as you don't try to disable DNSSEC or transfer your domain to a different DNS provider. You may find this blog post about Slack's DNSSEC-related outage useful: https://slack.engineering/what-happened-during-slacks-dnssec-rollout/ https://slack.engineering/what-happened-during-slacks-dnssec... One of Slack's issues was that Route 53 had a bug in their DNSSEC support, which is why I said "should" above.