
1/29/2015 · Ólafur Guðmundsson
What this post added
This post details Cloudflare's approach to implementing and deploying DNSSEC, focusing on signing at the edge on demand. It highlights the use of ECDSA P-256 for smaller signatures and improved performance, and a specialized NSEC implementation for negative answers to minimize response size and prevent zone walking. The author, a long-time DNSSEC expert, joined Cloudflare to contribute to this effort, emphasizing a fresh perspective and questioning prior assumptions.