This archive is retained to ensure existing URLs remain functional. It will not contain any emails sent to this mailing list after July 1, 2024. For all messages, including those sent before and after this date, please visit the new location of the archive at https://mailman.ripe.net/archives/list/dns-wg@ripe.net/
[dns-wg] DNSSEC and DNS slowdown
- Previous message (by thread): [dns-wg] DNSSEC and DNS slowdown
- Next message (by thread): [dns-wg] DNSSEC and DNS slowdown
Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
Dave Knight
dave at knig.ht
Fri Jul 30 15:30:54 CEST 2010
Hi Max, On 2010-07-30, at 7:14 AM, Max Tulyev wrote: > Hello! > > I have a strange problem. When I enable DNSSEC in my resolver (bind 9) - > it slows down in several times. > > What do I do wrong? Or may be it is a feature? Your question might be better asked over on <bind-users at isc.org>, however... Switching on DNSSEC validation gives the resolver more work to do, that might slow it down a bit, but not so you'd notice if things are working properly. If you're using a DLV it will have even more work to do, which might slow it down a bit more. If the path between your resolver and the authority servers isn't able to properly pass larger responses you might be suffering from timeouts which would slow it down a lot. A tcpdump at the resolver would probably be informative. dave
- Previous message (by thread): [dns-wg] DNSSEC and DNS slowdown
- Next message (by thread): [dns-wg] DNSSEC and DNS slowdown
Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
[ dns-wg Archives ]