Re: How are people implementing hold-down in RFC 5011?
Michael StJohns <[email protected]> Tue, 07 Oct 2014 16:10:41 -0400
| Newsgroups | gmane.ietf.dnsext |
|---|---|
| Message-ID | <[email protected]> |
At 04:03 PM 10/7/2014, Michael StJohns wrote: >So the above is actually "A and B sign (A Br D)". It's also actually more like "A and B sign (Br D and Z)" where "Z" is one of the ZSKs. So you get "B signs Br to revoke itself", "A signs D to add D to the trust anchor set" and "A signs Z so that Z chains to the root of trust". Sorry - This is actually "A and B sign (A Br D and Z)". A signing key needs to be included in the DNSKEY RRSet even if its already accepted as a trust anchor. That's mainly so the key id reference of the RRSIG (DNSKEY) can find the appropriate public key for validation. Mike _______________________________________________ dnsext mailing list [email protected] https://www.ietf.org/mailman/listinfo/dnsext