13 okt 2012 kl. 13:19 skrev James Cloos cloos@jhcloos.com:
Gnutls' design for dane seems to be the right approach in general for apps which want to do dnssec validation: provide options for whether to respect resolv.conf and whether to cache results. Its libdane links to libunbound but allows apps to choose whether to tell libunbound to parse resolv.conf and whether to cache results.
Apps which have config file should make those options start-time configurable.
That sounds reasonable. What's the architecture for OpenSSL?
/O