[DNSOP] Re: I-D Action: draft-ietf-dnsop-dnssec-keyrestore -02.txt
Ondřej Surý <[email protected]>
| Newsgroups | gmane.ietf.dnsop |
|---|---|
| Message-ID | <[email protected]> |
> It would be really helpful if others could try out the procedures mentioned in the document (with Knot or other implementations) to verify that the text is sufficiently clear. Martin, Florian, I am now confused - is Knot DNS the only implementation that you've tested then? Because you've only added Knot DNS into Implementation section, so now it looks like this can be only used with Knot DNS, but as far as I understand this is something that can be executed manually, right? So, when I asked about implementation section I imagined something like: with BIND 9, you need to do a, b, c, d... with Cascade, you need to e, f, g, h... with PowerDNS, you need to do ... with <whatelseyoutested>, you need to do... Can you clarify? Ondrej -- Ondřej Surý (He/Him) [email protected] A gentle nudge is always appreciated if I take a little longer to reply. > On 10. 8. 2026, at 09:28, Martin Pels <[email protected]> wrote: > > Hi, > > This version adds an implementation section, as requested during the working group session. We also added a paragraph about ZONEMD. > > It would be really helpful if others could try out the procedures mentioned in the document (with Knot or other implementations) to verify that the text is sufficiently clear. > > Kind regards, > Martin and Florian > > PS: Yes, we've introduced a typo in section 4.6 while moving the draft to the ietf-wg-dnsop repository. We will correct this in the next revision. > > -------- Forwarded Message -------- > Subject: [DNSOP] I-D Action: draft-ietf-dnsop-dnssec-keyrestore-02.txt > Date: Mon, 10 Aug 2026 00:13:57 -0700 > From: [email protected] > Reply-To: [email protected] > To: [email protected] > CC: [email protected] > > Internet-Draft draft-ietf-dnsop-dnssec-keyrestore-02.txt is now available. It > is a work item of the Domain Name System Operations (DNSOP) WG of the IETF. > > Title: DNSSEC Key Restore > Authors: Florian Obser > Martin Pels > Name: draft-ietf-dnsop-dnssec-keyrestore-02.txt > Pages: 12 > Dates: 2026-08-10 > > Abstract: > > This document describes the issues surrounding the handling of DNSSEC > private keys in a DNSSEC signer. It presents operational guidance in > case a DNSSEC private key becomes inoperable. > > Discussion Venues > > This note is to be removed before publishing as an RFC. > > Discussion of this document takes place on the Domain Name System > Operations Working Group mailing list ([email protected]), which is > archived at https://mailarchive.ietf.org/arch/browse/dnsop/. > > Source for this draft and an issue tracker can be found at > https://github.com/ietf-wg-dnsop/draft-ietf-dnsop-dnssec-keyrestore. > > The IETF datatracker status page for this Internet-Draft is: > https://datatracker.ietf.org/doc/draft-ietf-dnsop-dnssec-keyrestore/ > > There is also an HTML version available at: > https://www.ietf.org/archive/id/draft-ietf-dnsop-dnssec-keyrestore-02.html > > A diff from the previous version is available at: > https://author-tools.ietf.org/iddiff?url2=draft-ietf-dnsop-dnssec-keyrestore-02 > > Internet-Drafts are also available by rsync at: > rsync.ietf.org::internet-drafts > > > _______________________________________________ > DNSOP mailing list -- [email protected] > To unsubscribe send an email to [email protected] > > _______________________________________________ > DNSOP mailing list -- [email protected] > To unsubscribe send an email to [email protected] _______________________________________________ DNSOP mailing list -- [email protected] To unsubscribe send an email to [email protected]