Security/DNSSEC-TLS-details: Difference between revisions

m
no edit summary
(Created page with "== Background == For more background information on TLS and DNSSEC, click here. === Embedding Certificate Information in DNS === [http://tool...")
 
mNo edit summary
Line 87: Line 87:


Currently the second option (TLS extension) is considered ultimately more flexible and usable.
Currently the second option (TLS extension) is considered ultimately more flexible and usable.
== Test Plans ==
Current test plans (yet to be fully realized) include fuzzing the added attack surface (i.e. throwing data blobs at the validator) as well as deliberately crafted DNSSEC chains (e.g. ones with expired signatures, missing links, invalid links, etc.)
Confirmed users
299

edits