Re: Revision of 4310

Andrew Sullivan <[email protected]>
Newsgroups gmane.ietf.provreg
Message-ID <[email protected]>
On Tue, Jan 26, 2010 at 03:23:15PM -0500, Edward Lewis wrote:
>> I don't think I understand this one.  Do you mean that there's no
>> RRSIG for that DNSKEY record?
>
> To clarify - Yes.  In this instance, "in-active" would cover having a DS 
> appear, the DNSKEY appear, but no RRSIG created by the private key.  That 
> would make the DS "in-active" in terms of building a chain of trust.

I like this idea better than just not putting the DNSKEY in the DNSKEY
RRset.  Is anyone doing their deployment this way?

On the other hand, I suppose it doesn't really matter whether one does
it this way or by just not including the DNSKEY on the child side.  In
either case, you have to use the old key until the TTL expires
(because without an RRSIG, the new key won't be useful either).  So
why add the key to the DNSKEY RRset at all?

A

-- 
Andrew Sullivan
[email protected]
Shinkuro, Inc.
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
List run by majordomo software.  For (Un-)subscription and similar details
send "help" to [email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.