> > I've not been testing DNSSEC, but I understand it requires TCP. So, DNSSEC

> you might want to try it out to be sure of your understandings.

Yep. When I'm not sure of something, I usually say so.

> > cannot be deployed on root servers, due to large number of root servers
> > using anycast, and anycast conflict with the DNSSEC's TCP requirements.
> > (Anycast only works on UDP single packet per transaction protocols. ISC
> > mistakenly told root operators that anycast can be deployed with TCP.) So,

> they did? guess not everyone received the msg.

I suppose some people ignored the discussion of anycast on DNSOP. And
someone complained that anycast DNS root server operations weren't
relevant to Nanog. (bmanning)

And I haven't quite forgotten the rather vicious personal attack on me
made by John Brown on DNSOP, where he claimed to have no association with
ISC, even though he started chagres.net with Suzzanne Woolf who was the
ISC project manager in charge of promoting root anycast.

But I suppose that ISC hasn't made any efforts to get the message out. So
I have little doubt that not everyone has gotten the message.

