Observations on DNSSEC and ECDSA in the wild

Mr. Geoff Huston (APNIC)


This is a followup to a previous presentation to DNS OARC on the use of ECC as a digital signature algorithm. We report on the findings of a large scale field test of presentation of a DNS name signed using ECDSA, looking at the level of support in resolvers for DNSSEC validation and the behaviour when given a badly signed name.

