Hurricane Electric's IPv6 Tunnel Broker Forums

Tunnelbroker.net Specific Topics => Questions & Answers => Topic started by: kruton on November 17, 2013, 11:04:47 AM

Title: DNSSEC delegation for tunnel rDNS?
Post by: kruton on November 17, 2013, 11:04:47 AM
Is DNSSEC delegation for rDNS in the plan as well? Right now I'm using ISC's DLV registry, but the IPv6 rDNS is the last thing listed there for me.

I noticed that HE.net's IPv6 delegation is not signed even though ARIN's is:
http://dnsviz.net/d/0.7.4.0.1.0.0.2.ip6.arpa/dnssec/
Title: Re: DNSSEC delegation for tunnel rDNS?
Post by: snarked on November 17, 2013, 12:02:37 PM
I don't see that as happening right now because HE's name servers aren't issuing DNSSEC records for zones that are signed regardless of how "the chain of trust" is delegated.  We should ask again when their name server software has been upgraded.

General rant:  There are still TLDs that don't even have IPv6 addresses for their servers let alone DNSSEC.  The real problem may be with ICANN.