logoalt Hacker News

ekr____yesterday at 7:43 PM0 repliesview on HN

It's actually not safe for clients to perform local validation because a quite significant fraction of middleboxes and the like strip out RRSIG and the like or otherwise tamper with the records in such a way that the signatures don't validate.