Last Updated: 2011-04-14 02:26:28 UTC
by Johannes Ullrich (Version: 1)
To coincide with today's webcast about DNSSEC , I changed how the dshield.org zone is DNSSEC signed. The zone itself has been signed for a while now, but I used "look aside validation" via isc.org . For a few months now, it has been possible to have .org zones directly signed by .org, and I decided to give it a try. Please let me know if you see any issues. If you plan to deploy DNSSEC yourself, see Verisign's  nice testing tool as well as the visualization tool by DNSVIZ .