Dans le pdf indiqué en lien ("improving TCP security with robust cookies") on trouve ceci :
"Common DNSSEC-signed responses are as long as 1749 bytes. During key rollover, the response could be more than twice that size, much larger than the default UDP data size of 512 bytes".
[^] # Re: DNSSEC et UDP
Posté par patrick_g (site web personnel) . En réponse à la dépêche Nouvelle version 2.6.33 du noyau Linux. Évalué à 2.
"Common DNSSEC-signed responses are as long as 1749 bytes. During key rollover, the response could be more than twice that size, much larger than the default UDP data size of 512 bytes".