@lanodan Many things:
- HSM used might not be able to handle ECDSA (well, just learned that hardware will change)
- 4096-bits RSA produces larger signatures. Not really adequate for DNS (and takes longer to sign)
- Out-of-age big companies not able to work with ECDSA (pretty sure there is still lots of big resolvers too old for that)
Embed Notice
HTML Code
Corresponding Notice
- Embed this notice
John Shaft (shaft@piaille.fr)'s status on Wednesday, 20-Sep-2023 22:45:32 JSTJohn Shaft