Answer the question
In order to leave comments, you need to log in
Does DNSSEC and TLSA somehow affect the order in which a client communicates with DNS servers? And does TLSA make sense?
I want to set up DNSSEC and TLSA on my site, but this will likely require me to move to a different registrar and to different NS servers that are geographically much farther away from the audience than the current ones as my registrar is having a hard time supporting DNSSEC , CloudFlare doesn't support TLSA, and it's too expensive for NS to keep its BIND (or whatever people usually do) at this stage.
Therefore, I want to ask, after enabling DNSSEC and TLSA, will anything change in the order in which DNS records are received by clients? Will it still be one request to the caching server they use (8.8.8.8 or something) and one response from it?
And does any TLSA even make sense?
Clients are assumed to be using public DNS like 8.8.8.8.
Answer the question
In order to leave comments, you need to log in
Didn't find what you were looking for?
Ask your questionAsk a Question
731 491 924 answers to any question