Example of stupid inconsistencies between registries
Patrik Fältström <[email protected]>
| Newsgroups | gmane.ietf.provreg |
|---|---|
| Message-ID | <[email protected]> |
According to RFC 5910, section 4, there are two alternative interfaces for managing DNSSEC key data when interfacing with a registry. The RFC does not explicitly say whether a registry must implement one or the other. I have successfully implemented in a web interface, an API for registrants etc, the DS interface as the client do believe passing DS data is the easiest. After all that is what is to be signed by the parent. I just encountered a registry that "want to set a limit on what digest algorithms to use" and to do that, they have decided to not implement the DS interface and only support the KEY interface. I can accept limitations on what digest algorithms they accept, but not limitations by not supporting DS. Reactions? Patrik _______________________________________________ provreg mailing list [email protected] https://www.ietf.org/mailman/listinfo/provreg