Re: How are people implementing hold-down in RFC 5011?

Michael StJohns <[email protected]> Tue, 07 Oct 2014 16:10:41 -0400
Newsgroups gmane.ietf.dnsext
Message-ID <[email protected]>
At 04:03 PM 10/7/2014, Michael StJohns wrote:
>So the above is actually "A and B sign (A Br D)".  It's also actually more like "A and B sign (Br D and Z)" where "Z" is one of the ZSKs.  So you get "B signs Br to revoke itself", "A signs D to add D to the trust anchor set" and "A signs Z so that Z chains to the root of trust".  


Sorry - 

This is actually "A and B sign (A Br D and Z)".

A signing key needs to be included in the DNSKEY RRSet even if its already accepted as a trust anchor.  That's mainly so the key id reference of the RRSIG (DNSKEY) can find the appropriate public key for validation. 

Mike




_______________________________________________
dnsext mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/dnsext