Re: Example of stupid inconsistencies between registries

Andrew Sullivan <[email protected]>
Newsgroups gmane.ietf.provreg
Message-ID <[email protected]>
On Mon, Mar 05, 2012 at 09:48:04AM -0500, MICHAEL YOUNG wrote:
> Ok I see this argument but on the other hand I have to ask how much
> responsibility does the registry want to take on? 

The registry took on the responsibility for authoritative data in its
zone by virtue of accepting the delegation from its parent (usually
the root).  You might as well argue that the registry doesn't really
have to keep its apex records well-maintained.

> verify the DS data.  However, lets face it, I can publish whatever I
> want to the registry and then later on mess my zone up because I
> mis-manage something.

That's just irrelevant.  The issue here is data that is authoritative
_only_ in the parent-side zone.

> Besides, if the DS data is wrong, then DNSSEC validation is just
> going to choke anyways right? 

Could be, but you might not know it.

One rollover mechanism is to pre-publish a DS record on the parent
side of the zone cut before you publish the DNSKEY on the child side.
You generate RRSIGs with the stand-by key as well, but never publish
the new DNSKEY until the end; this way you always have a stand-by key
in place, so that if your active key is compromised you just publish
the new key and remove the old key.  Your exposure in that case is
only as long as the TTL on the DNSKEY record.

A

-- 
Andrew Sullivan
[email protected]
_______________________________________________
provreg mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/provreg
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.