Re: [Editorial Errata Reported] RFC6840 (4191)
Jelte Jansen <[email protected]> Wed, 3 Dec 2014 09:51:37 +0100
| Newsgroups | gmane.ietf.dnsext |
|---|---|
| Message-ID | <[email protected]> |
On 12/02/2014 09:21 PM, Brian Haberman wrote: > Despite Donald's assertion, I think this is a valid erratum and should > be marked Verified. However, I will wait for others to chime in on the > subject before doing so. > I see a few pros and cons; yes the proposed text is correct and better than the original. However, this is not the only place that 'signing the zone' is used, and used with the meaning 'signing each authoritative RRset within the zone' in the set of RFC4033-4035 (and possibly outside of those as well). But I have had people ask me what 'signing the zone' actually means, usually in the context of KSK vs ZSK (and hence, is the DNSKEY set part of 'the zone'), not necesarily in the context of algorithm downgrade protection. Then again, RFC4033 actually defines a 'signed zone' as 'A zone whose RRsets are signed and ...'. So while signing full zones in AXFRs might add confusion here, I do think it is stated correctly as it is. Then again (again), that is about whether there are signatures at all and 'signed' there doesn't mention signed by what (keys/algorithms/autographs). So I don't think the errata is necessary, but I wouldn't exactly be opposed either. Jelte _______________________________________________ dnsext mailing list [email protected] https://www.ietf.org/mailman/listinfo/dnsext