1 | | In addition to the lack of (full) support for subdomain zone by Hetzner, I've also bumped into the lack of support for DNSSEC delegation for subdomains: most registrars, when they do support DNSSEC, only allows the owner to manage DS keys to a (2nd level) domain (e.g. tahoe-lafs.org). |
2 | | Which means the chain of trust will be broken for any subdomain (e.g. of.tahoe-lafs.org). |
| 1 | In addition to the lack of (full) support for subdomain zone by Hetzner, I've also bumped into the lack of support for DNSSEC delegation for subdomains: most registrars, when they do support DNSSEC, only allows the owner to manage DS keys to a (2nd level) domain (e.g. `tahoe-lafs.org `). |
| 2 | Which means the chain of trust will be broken for any subdomain (e.g. `of.tahoe-lafs.org`). |