Re: [Editorial Errata Reported] RFC6840 (4191)

Brian Haberman <[email protected]> Tue, 02 Dec 2014 15:21:19 -0500
Newsgroups gmane.ietf.dnsext
Message-ID <[email protected]>
Despite Donald's assertion, I think this is a valid erratum and should
be marked Verified.  However, I will wait for others to chime in on the
subject before doing so.

Regards,
Brian

On 12/2/14 11:36 AM, RFC Errata System wrote:
> The following errata report has been submitted for RFC6840,
> "Clarifications and Implementation Notes for DNS Security (DNSSEC)".
> 
> --------------------------------------
> You may review the report below and at:
> http://www.rfc-editor.org/errata_search.php?rfc=6840&eid=4191
> 
> --------------------------------------
> Type: Editorial
> Reported by: Edward Lewis <[email protected]>
> 
> Section: 5.11
> 
> Original Text
> -------------
> ...
> 
> A signed zone MUST include a DNSKEY for each algorithm present in
>       the zone's DS RRset and expected trust anchors for the zone.  The
>       zone MUST also be signed with each algorithm (though not each key)
>       present in the DNSKEY RRset.  
> 
> Corrected Text
> --------------
> A signed zone MUST include a DNSKEY for each algorithm present in
>       the zone's DS RRset and expected trust anchors for the zone.  Each
>       authoritative RRset in the zone MUST be signed with each 
>       algorithm (though not each key) present in the DNSKEY RRset.  
> 
> Notes
> -----
> Zones aren't signed (per se), the data sets within them are.  But not cut point (NS) and glue.
> 
> Instructions:
> -------------
> This erratum is currently posted as "Reported". If necessary, please
> use "Reply All" to discuss whether it should be verified or
> rejected. When a decision is reached, the verifying party (IESG)
> can log in to change the status and edit the report, if necessary. 
> 
> --------------------------------------
> RFC6840 (draft-ietf-dnsext-dnssec-bis-updates-20)
> --------------------------------------
> Title               : Clarifications and Implementation Notes for DNS Security (DNSSEC)
> Publication Date    : February 2013
> Author(s)           : S. Weiler, Ed., D. Blacka, Ed.
> Category            : PROPOSED STANDARD
> Source              : DNS Extensions
> Area                : Internet
> Stream              : IETF
> Verifying Party     : IESG
>

_______________________________________________
dnsext mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/dnsext
signature.asc (application/pgp-signature, 536 B)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG/MacGPG2 v2.0.20 (Darwin)
Comment: GPGTools - https://gpgtools.org

iQEcBAEBCgAGBQJUfh9FAAoJEBOZRqCi7goqw+QIAIWTWGTSt7ULBbR+0wdAnZxu
5ROESijH8DEMyeWjZceEstHA0HQjuQ9H142434XvVH/XZYP45l4afqkRKVR7EfFC
63AbMNbDKpLV1oKgs6KYYiUQvxAlspSvuG9CtfaP2Xw2kq3/NXNJX/JGet2a2OKq
YJNH4H3X1GC5jM0jADLZEeDZjsl8ShEjpZ7Sy0ZQcGm7Io52U4qaujQAqYiI1RZ6
Z/BYT8wrJvgT175UDpSReDcK2/bItKYjKAWHQiUhLajMVLRRtU2hppyxDAq6wp/J
Jipip/wg9CGrng1oadvZomS8UtJk+CgUq1C5PM1k1hK2mwOH5V3A2gO+JTbBV4o=
=fxfb
-----END PGP SIGNATURE-----