|
|
|
|
|
by tptacek
1718 days ago
|
|
The USG DNSSEC requirements, which seem to be a part of what happened, are fragmented and incoherent. OMB withdrew DNSSEC requirements in 2018, and CLOUD.GOV doesn't support it. But some older requirements documents still have them, and need to be updated. The important top-line thing to know here is that virtually all tech companies eschew DNSSEC (you can verify that for yourself with `host -t ds stripe.com`; substitute any other company for Stripe. DNSSEC-quarantine TLDs are a good idea. |
|
https://cloud.gov/docs/compliance/domain-standards/#dnssec