Re: draft-kong-epp-cdn-dnssec-mapping-00 Submitted for Review
"Gould, James" <[email protected]>
| Newsgroups | gmane.ietf.provreg |
|---|---|
| Message-ID | <CACED2D4.1A5A8%[email protected]> |
Peter, Yes, you are correct that inheriting the DNSKEY of the OCDN across the CDN's would work and the server would then generate the set of DS across the OCDN and it's CDN's. I guess the only question is whether you would really want to share / inherit the key material, but that might make sense for related domains like OCDN and CDN's. I like the OCDN and CDN's to be treated as separate entities, but if the CDN's are contained by the OCDN and have to inherit the OCDN attributes, than use of the DNSKEY with the Key Data Interface of RFC 5910 should meet the goal. -- JG James Gould Principal Software Engineer [email protected] 703-948-3271 21345 Ridgetop Circle LS2-2-1 Dulles, VA 20166 VerisignInc.com On 10/27/11 4:45 AM, "Peter Koch" <[email protected]> wrote: >On Wed, Oct 26, 2011 at 05:03:54PM +0800, Ning Kong wrote: > >> > Are you saying that the CDN's inherit all of the attributes of the >>OCDN >> > except for the DNSSEC attributes that can't? >> Yes. Actually we hope all the CDNs could inherit all of the atrributes >> of the OCDN. But because the DS must be bound with the name of CDN, so >> the DNSSEC attributes of CDNs can't be same. > >so, why not operate on DNSKEY only - instead of DS? > >-Peter >_______________________________________________ >provreg mailing list >[email protected] >https://www.ietf.org/mailman/listinfo/provreg _______________________________________________ provreg mailing list [email protected] https://www.ietf.org/mailman/listinfo/provreg