[Editorial Errata Reported] RFC6840 (4191)
RFC Errata System <[email protected]> Tue, 2 Dec 2014 08:36:46 -0800 (PST)
| Newsgroups | gmane.ietf.dnsext |
|---|---|
| Message-ID | <[email protected]> |
The following errata report has been submitted for RFC6840, "Clarifications and Implementation Notes for DNS Security (DNSSEC)". -------------------------------------- You may review the report below and at: http://www.rfc-editor.org/errata_search.php?rfc=6840&eid=4191 -------------------------------------- Type: Editorial Reported by: Edward Lewis <[email protected]> Section: 5.11 Original Text ------------- ... A signed zone MUST include a DNSKEY for each algorithm present in the zone's DS RRset and expected trust anchors for the zone. The zone MUST also be signed with each algorithm (though not each key) present in the DNSKEY RRset. Corrected Text -------------- A signed zone MUST include a DNSKEY for each algorithm present in the zone's DS RRset and expected trust anchors for the zone. Each authoritative RRset in the zone MUST be signed with each algorithm (though not each key) present in the DNSKEY RRset. Notes ----- Zones aren't signed (per se), the data sets within them are. But not cut point (NS) and glue. Instructions: ------------- This erratum is currently posted as "Reported". If necessary, please use "Reply All" to discuss whether it should be verified or rejected. When a decision is reached, the verifying party (IESG) can log in to change the status and edit the report, if necessary. -------------------------------------- RFC6840 (draft-ietf-dnsext-dnssec-bis-updates-20) -------------------------------------- Title : Clarifications and Implementation Notes for DNS Security (DNSSEC) Publication Date : February 2013 Author(s) : S. Weiler, Ed., D. Blacka, Ed. Category : PROPOSED STANDARD Source : DNS Extensions Area : Internet Stream : IETF Verifying Party : IESG _______________________________________________ dnsext mailing list [email protected] https://www.ietf.org/mailman/listinfo/dnsext