[DNSOP] Re: I-D Action: draft-ietf-dnsop-dnssec-keyrestore -02.txt
"Martin Pels (RIPE NCC)" <[email protected]>
| Newsgroups | gmane.ietf.dnsop |
|---|---|
| Message-ID | <[email protected]> |
Hi Ondřej, On 27/08/2026 14:00, Ondřej Surý wrote: >> It would be really helpful if others could try out the procedures mentioned in the document (with Knot or other implementations) to verify that the text is sufficiently clear. > > Martin, Florian, > > I am now confused - is Knot DNS the only implementation that you've tested then? Because you've only added Knot DNS into Implementation section, so now it looks > like this can be only used with Knot DNS, but as far as I understand this is something that can be executed manually, right? > > So, when I asked about implementation section I imagined something like: > > with BIND 9, you need to do a, b, c, d... > with Cascade, you need to e, f, g, h... > with PowerDNS, you need to do ... > with <whatelseyoutested>, you need to do... > > Can you clarify? We have only added Knot to the implementation section since that is the implementation we use for our own signers, and it is indeed the only one we have tested the procedure with ourselves. In theory, the procedure should be possible with any implementation, as long as it does not try to be too smart (e.g. it will allow you to load a zone with additional RRSIGs for which a signing key is no longer available). There was some concern raised during the WG session that it will not work with Cascade in its current design. Maybe Philip could comment on this. Kind regards, Martin _______________________________________________ DNSOP mailing list -- [email protected] To unsubscribe send an email to [email protected]