[Cryptography] Against against DNS (Re: New SSL/TLS certs to each live no longer than 47) days by 2029
Peter Gutmann
pgut001 at cs.auckland.ac.nz
Fri Apr 25 22:21:08 EDT 2025
David Conrad writes:
>APNIC, an IP address registry, has essentially no role in deploying DNSSEC.
Oops, sorry, you're right, I was thinking of APNIC Labs but that's more
participating than deploying.
As an interesting aside and speaking of said labs, the region with the best
deployment of DNSSEC seems to be Africa, which also happens to be the region
with the least Internet connectivity:
https://stats.labs.apnic.net/dnssec
Places like Guinea-Bissau and Uganda (and in fact most of the rest of Africa)
have better DNSSEC deployment than the US and Canada. It'd be interesting to
know why this is the case - one guess is that if there's very little there in
the first place then just a small amount of DNSSEC makes a huge difference.
Peter.
More information about the cryptography
mailing list