On Fri, Feb 3, 2012 at 9:53 AM, Cricket Liu <span dir="ltr"><<a href="mailto:cricket@infoblox.com">cricket@infoblox.com</a>></span> wrote:<br><div class="gmail_quote"><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
<div class="im">This is consistent with something I noticed earlier: DNSViz validates <a href="http://oppedahl.com" target="_blank">oppedahl.com</a>'s chain of trust without a problem, but Verisign Labs' DNSSEC Debugger reports no response from <a href="http://oppedahl.com" target="_blank">oppedahl.com</a>'s name servers. DNSViz is hosted by Sandia, presumably in New Mexico, while Verisign Labs is in the D.C. area.</div>
<br></blockquote><div><br></div><div>FWIW, DNSViz is actually hosted out of Sandia's Livermore, CA, site, in the SF Bay Area :)</div><div><br></div><div>Geography aside, issues such as anycast instances and resolver perspective are things I plan to address for DNSViz to make it a more useful tool. We're looking to procure funding to continue work on it in these areas and others.</div>
<div><br></div><div>Casey</div></div>