On Thu, 20 Mar 2003, Bill Sommerfeld wrote: > An alternate approach which I think is superior is to ensure that the > DNS search path used while resolving SSHFP records comes from a > trusted source (i.e., not from DHCP or PPP/ipcp). or one could just acknowledge that DNS search paths are evil. jakob