logoalt Hacker News

thaynetoday at 1:30 AM3 repliesview on HN

Probably the most common reason to use DNSSEC is to check a box on a list of compliance rules. And I don't think this will change anything for people who need DNSSEC for compliance.


Replies

tptacektoday at 2:23 AM

There's no commercial compliance regime that requires DNSSEC (FedRAMP might be the only exception --- I'm uncertain about the current state of FedRAMP DNSSEC rules --- but that makes sense given that DNSSEC is a giant key escrow scheme.)

show 1 reply
whhtoday at 9:33 AM

I found another reason... MS365 require DNSSEC to be enabled if you want DANE for TLS-enforced SMTP. You could also use MTA-STS.

pocksuppettoday at 2:27 AM

Probably the most common reason to use TLS is to check a box on a list of compliance rules. Is that bad?

show 2 replies