diff options
Diffstat (limited to 'doc/dnssec-guide')
-rw-r--r-- | doc/dnssec-guide/introduction.rst | 2 | ||||
-rw-r--r-- | doc/dnssec-guide/validation.rst | 2 |
2 files changed, 2 insertions, 2 deletions
diff --git a/doc/dnssec-guide/introduction.rst b/doc/dnssec-guide/introduction.rst index 7f13155..f0d0d9d 100644 --- a/doc/dnssec-guide/introduction.rst +++ b/doc/dnssec-guide/introduction.rst @@ -372,7 +372,7 @@ want to consider deploying DNSSEC: .. [#] The Office of Management and Budget (OMB) for the US government published `a memo in - 2008 <https://www.whitehouse.gov/sites/whitehouse.gov/files/omb/memoranda/2008/m08-23.pdf>`__, + 2008 <https://georgewbush-whitehouse.archives.gov/omb/memoranda/fy2008/m08-23.pdf>`__, requesting all ``.gov`` subdomains to be DNSSEC-signed by December 2009. This explains why ``.gov`` is the most-deployed DNSSEC domain currently, with `around 90% of subdomains diff --git a/doc/dnssec-guide/validation.rst b/doc/dnssec-guide/validation.rst index 98696bb..07ab349 100644 --- a/doc/dnssec-guide/validation.rst +++ b/doc/dnssec-guide/validation.rst @@ -717,7 +717,7 @@ process. Thereafter, BIND uses the managed keys database Explicit management of keys was common in the early days of DNSSEC, when neither the root zone nor many top-level domains were signed. Since -then, `over 90% <https://stats.research.icann.org/dns/tld_report/>`__ of +then, `over 90% <https://ithi.research.icann.org/graph-m7.html>`__ of the top-level domains have been signed, including all the largest ones. Unless you have a particular need to manage keys yourself, it is best to use the BIND defaults and let the software manage the root key. |