logoalt Hacker News

AndroTuxyesterday at 10:16 PM1 replyview on HN

What if the root (.) certificate breaks?


Replies

pocksuppetyesterday at 10:22 PM

Resolvers are free to cache each TLD's keys. There's a finite, well-known list of TLDs and their keys - you can download all the root zone data from IANA: https://www.iana.org/domains/root/files (it's a few megabytes in uncompressed text form)

The world might be a little bit better with more decentralization of the root zone.