Re: Example of stupid inconsistencies between registries
Andrew Sullivan <[email protected]>
| Newsgroups | gmane.ietf.provreg |
|---|---|
| Message-ID | <[email protected]> |
On Mon, Mar 05, 2012 at 09:48:04AM -0500, MICHAEL YOUNG wrote: > Ok I see this argument but on the other hand I have to ask how much > responsibility does the registry want to take on? The registry took on the responsibility for authoritative data in its zone by virtue of accepting the delegation from its parent (usually the root). You might as well argue that the registry doesn't really have to keep its apex records well-maintained. > verify the DS data. However, lets face it, I can publish whatever I > want to the registry and then later on mess my zone up because I > mis-manage something. That's just irrelevant. The issue here is data that is authoritative _only_ in the parent-side zone. > Besides, if the DS data is wrong, then DNSSEC validation is just > going to choke anyways right? Could be, but you might not know it. One rollover mechanism is to pre-publish a DS record on the parent side of the zone cut before you publish the DNSKEY on the child side. You generate RRSIGs with the stand-by key as well, but never publish the new DNSKEY until the end; this way you always have a stand-by key in place, so that if your active key is compromised you just publish the new key and remove the old key. Your exposure in that case is only as long as the TTL on the DNSKEY record. A -- Andrew Sullivan [email protected] _______________________________________________ provreg mailing list [email protected] https://www.ietf.org/mailman/listinfo/provreg