logoalt Hacker News

UltraSaneyesterday at 6:38 PM1 replyview on HN

And route53 makes DNSSEC very easy to enable so all the DNS data is cryptographic signed. This makes putting public keys and certificates in DNS much more sensible.


Replies

cbm-vic-20yesterday at 7:07 PM

I dug into the DNSSEC rabbit hole a few weeks ago and got drawn into the fascinating root key signing ceremony.

https://www.iana.org/dnssec/ceremonies/62