Too many times over the last few weeks, you heard that the real answer to
all the DNS problems is DNSSEC. I decided to give it a try, and signed the
dshield.org zone. DNSSEC is not exactly used very widely, and it is very
possible that we will be running into some problems. If you experience any
issues, please let us know (via isc.sans.org ;-) ). For most users, this
will not change anything. It only matters if your resolver or your web
browser actually verifies DNSSEC signature. Expect a few changes to our
dshield.org zone while I experiment.
"Never drive faster than your ANGEL can fly"