Re: [Editorial Errata Reported] RFC6840 (4191)

Jelte Jansen <[email protected]> Wed, 3 Dec 2014 09:51:37 +0100
Newsgroups gmane.ietf.dnsext
Message-ID <[email protected]>
On 12/02/2014 09:21 PM, Brian Haberman wrote:
> Despite Donald's assertion, I think this is a valid erratum and should
> be marked Verified.  However, I will wait for others to chime in on the
> subject before doing so.
> 

I see a few pros and cons; yes the proposed text is correct and better
than the original. However, this is not the only place that 'signing the
zone' is used, and used with the meaning 'signing each authoritative
RRset within the zone' in the set of RFC4033-4035 (and possibly outside
of those as well).

But I have had people ask me what 'signing the zone' actually means,
usually in the context of KSK vs ZSK (and hence, is the DNSKEY set part
of 'the zone'), not necesarily in the context of algorithm downgrade
protection.

Then again, RFC4033 actually defines a 'signed zone' as 'A zone whose
RRsets are signed and ...'. So while signing full zones in AXFRs might
add confusion here, I do think it is stated correctly as it is.

Then again (again), that is about whether there are signatures at all
and 'signed' there doesn't mention signed by what
(keys/algorithms/autographs).

So I don't think the errata is necessary, but I wouldn't exactly be
opposed either.

Jelte

_______________________________________________
dnsext mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/dnsext