Get the latest tech news
The Promised LAN
The Internet sucks, build a LAN
There are a set of root DNS servers ( ns1.tpl, ns2.tpl, ns3.tpl) which are hosted on three different LANs which are each connected to a different backbone node, in the event of network outages. By convention (mostly to avoid managing a bunch of ), we expect that each LAN runs their own authoritative nameserver at the fixed IP of x.x.x.254. Finally, we figured we'd use our existing DNS for managing our x509 certificate issuance — so we don't have to send CSR s around and wait for human action.
Or read this on Hacker News