Re: [Editorial Errata Reported] RFC6840 (4191)
Paul Hoffman <[email protected]> Wed, 3 Dec 2014 08:37:53 -0800
| Newsgroups | gmane.ietf.dnsext |
|---|---|
| Message-ID | <[email protected]> |
On Dec 3, 2014, at 12:51 AM, Jelte Jansen <[email protected]> wrote: > I see a few pros and cons; yes the proposed text is correct and better > than the original. However, this is not the only place that 'signing the > zone' is used, and used with the meaning 'signing each authoritative > RRset within the zone' in the set of RFC4033-4035 (and possibly outside > of those as well). > > But I have had people ask me what 'signing the zone' actually means, > usually in the context of KSK vs ZSK (and hence, is the DNSKEY set part > of 'the zone'), not necesarily in the context of algorithm downgrade > protection. > > Then again, RFC4033 actually defines a 'signed zone' as 'A zone whose > RRsets are signed and ...'. So while signing full zones in AXFRs might > add confusion here, I do think it is stated correctly as it is. Just to drive the point home a bit further, since you brought up the definition in RFC 4033: Signed Zone: A zone whose RRsets are signed and that contains properly constructed DNSKEY, Resource Record Signature (RRSIG), Next Secure (NSEC), and (optionally) DS records. A developer asked me a few years ago "does that mean that all the RRsets are signed? What if just the A records are signed?" That's a valid question given the definition. It is only by reading the rest of the document do you get the feeling (but never the actual statement) that it means *all* of the RRsets in the zone. --Paul Hoffman _______________________________________________ dnsext mailing list [email protected] https://www.ietf.org/mailman/listinfo/dnsext