Re: Example of stupid inconsistencies between registries
Peter Koch <[email protected]>
| Newsgroups | gmane.ietf.provreg |
|---|---|
| Message-ID | <[email protected]> |
Patrik, > A registry that want to be "thick" can still receive the DS, then fetch the DNSKEY from DNS which they validate against the DS. If they want create a new DS they can do so with whatever digest algorithm they want and not even publish the DS that the client passes to them. i'm not sure what exactly you mean by thick (or "fat", as others have said) vs. thin here since in the realm of registries these terms are already occupied. I think the validation is related to, but otherwise independent of the type of object passed. In your scenario any DNSKEY that would end up in the registry db would have to be present at the apex at the time of registration, which prohibits pre-publication of a DS RR for a DNSKEY not yet present at the apex DNSKEY RRSet. I don't understand how the DNSKEY would be worse for the registrant than the DS given that the DNSKEY is what they already have in their hands. -Peter _______________________________________________ provreg mailing list [email protected] https://www.ietf.org/mailman/listinfo/provreg