DNSSEC
Observations from the DNSSEC deployment
Tue, 05/20/2008 - 15:43 by Sébastien Barré • Categories:
This paper by E. Osterwell, D. Massey and L. Zhang describes the experience learned from their tool, secspider (http://secspider.cs.ucla.edu/).
After introducing DNSSEC, they show that DNSSEC is currently not widely deployed, and many "islands of security" exists. An island of security is a (set of) zone(s) that have deployed DNSSEC, but their parent have not DNSSEC. Thus the trust chain cannot be established. In particular the root servers have not enabled DNSSEC.