logoalt Hacker News

UltraSanetoday at 6:38 PM1 replyview on HN

And route53 makes DNSSEC very easy to enable so all the DNS data is cryptographic signed. This makes putting public keys and certificates in DNS much more sensible.


Replies

cbm-vic-20today at 7:07 PM

I dug into the DNSSEC rabbit hole a few weeks ago and got drawn into the fascinating root key signing ceremony.

https://www.iana.org/dnssec/ceremonies/62