Re: rfc4310bis 03 AD Feedback
| Newsgroups | gmane.ietf.provreg |
|---|---|
| Message-ID | <OF290E454A.30980263-ON802576B9.00576302-802576B9.0057F86A@nominet.org.uk> |
> An OPTIONAL <secDNS:maxSigLife> element that indicates a child's > preference for the number of seconds after signature generation > when the parent's signature on the DS information provided by the > child will expire. A client SHOULD specify the same <secDNS: > maxSigLife> value for all <secDNS:dsData> elements associated with > a domain. If the <secDNS:maxSigLife> is not present, or if > multiple <secDNS:maxSigLife> values are requested, the default > signature expiration policy of the server operator (as determined > using an out-of-band mechanism) applies Please forgive my ignorance, as I wasn't around when 4310 was written. What's the rationale for giving the child _any_ say in the DS record signature lifetimes as presented in the parent zone? kind regards, Ray -- Ray Bellis, MA(Oxon) MIET Senior Researcher in Advanced Projects, Nominet e: [email protected], t: +44 1865 332211