Re: [Editorial Errata Reported] RFC6840 (4191)
Brian Haberman <[email protected]> Tue, 02 Dec 2014 15:21:19 -0500
| Newsgroups | gmane.ietf.dnsext |
|---|---|
| Message-ID | <[email protected]> |
Despite Donald's assertion, I think this is a valid erratum and should be marked Verified. However, I will wait for others to chime in on the subject before doing so. Regards, Brian On 12/2/14 11:36 AM, RFC Errata System wrote: > The following errata report has been submitted for RFC6840, > "Clarifications and Implementation Notes for DNS Security (DNSSEC)". > > -------------------------------------- > You may review the report below and at: > http://www.rfc-editor.org/errata_search.php?rfc=6840&eid=4191 > > -------------------------------------- > Type: Editorial > Reported by: Edward Lewis <[email protected]> > > Section: 5.11 > > Original Text > ------------- > ... > > A signed zone MUST include a DNSKEY for each algorithm present in > the zone's DS RRset and expected trust anchors for the zone. The > zone MUST also be signed with each algorithm (though not each key) > present in the DNSKEY RRset. > > Corrected Text > -------------- > A signed zone MUST include a DNSKEY for each algorithm present in > the zone's DS RRset and expected trust anchors for the zone. Each > authoritative RRset in the zone MUST be signed with each > algorithm (though not each key) present in the DNSKEY RRset. > > Notes > ----- > Zones aren't signed (per se), the data sets within them are. But not cut point (NS) and glue. > > Instructions: > ------------- > This erratum is currently posted as "Reported". If necessary, please > use "Reply All" to discuss whether it should be verified or > rejected. When a decision is reached, the verifying party (IESG) > can log in to change the status and edit the report, if necessary. > > -------------------------------------- > RFC6840 (draft-ietf-dnsext-dnssec-bis-updates-20) > -------------------------------------- > Title : Clarifications and Implementation Notes for DNS Security (DNSSEC) > Publication Date : February 2013 > Author(s) : S. Weiler, Ed., D. Blacka, Ed. > Category : PROPOSED STANDARD > Source : DNS Extensions > Area : Internet > Stream : IETF > Verifying Party : IESG > _______________________________________________ dnsext mailing list [email protected] https://www.ietf.org/mailman/listinfo/dnsext
signature.asc
(application/pgp-signature, 536 B)
-----BEGIN PGP SIGNATURE----- Version: GnuPG/MacGPG2 v2.0.20 (Darwin) Comment: GPGTools - https://gpgtools.org iQEcBAEBCgAGBQJUfh9FAAoJEBOZRqCi7goqw+QIAIWTWGTSt7ULBbR+0wdAnZxu 5ROESijH8DEMyeWjZceEstHA0HQjuQ9H142434XvVH/XZYP45l4afqkRKVR7EfFC 63AbMNbDKpLV1oKgs6KYYiUQvxAlspSvuG9CtfaP2Xw2kq3/NXNJX/JGet2a2OKq YJNH4H3X1GC5jM0jADLZEeDZjsl8ShEjpZ7Sy0ZQcGm7Io52U4qaujQAqYiI1RZ6 Z/BYT8wrJvgT175UDpSReDcK2/bItKYjKAWHQiUhLajMVLRRtU2hppyxDAq6wp/J Jipip/wg9CGrng1oadvZomS8UtJk+CgUq1C5PM1k1hK2mwOH5V3A2gO+JTbBV4o= =fxfb -----END PGP SIGNATURE-----