1 Apr 2005 08:49
Re: paragraph 4.4.2 in dnssec-operational-practices-03
Marcos Sanz/Denic <sanz <at> denic.de>
2005-04-01 06:49:53 GMT
2005-04-01 06:49:53 GMT
Miek, > Sam argues: > Section 4.4.2 suggests storing DNSKEYs, not DSs. I think this is bad > advice -- DS message digest algorithms may be used for signaling (of, > for example, use of NSEC3), so the child may want to choose the > message digest algorithm. Rather than require the parent to > support them all, why not just let the child provide the hash? > > I argue: > My opinion in this is that the DS is a parental record and as such a child may > not even be aware that it exists. This reminds me of the discussion had not a long time ago about the epp-dnssec documents. There, we achieved consensus about the child providing the DS record to the parent and *optionally* key information (and so reflects it epp-secdns-07). IMHO operational practices should be coherent with that (well, or the other way round). Regards, Marcos . dnsop resources:_____________________________________________________ web user interface: http://darkwing.uoregon.edu/~llynch/dnsop.html mhonarc archive: http://darkwing.uoregon.edu/~llynch/dnsop/index.html
.
Olaf, I asked the IESG to review my document yesterday. It's finished
(barring last call and IESG review issues) as far as I'm concerned.
The rationale is described in the archives of this mailing list. However,
it's probably better that the material be included in your document since
yours is specifically focused on operational practices.
-
RSS Feed