Re: Example of stupid inconsistencies between registries

Peter Koch <[email protected]>
Newsgroups gmane.ietf.provreg
Message-ID <[email protected]>
Patrik,

> A registry that want to be "thick" can still receive the DS, then fetch the DNSKEY from DNS which they validate against the DS. If they want create a new DS they can do so with whatever digest algorithm they want and not even publish the DS that the client passes to them.

i'm not sure what exactly you mean by thick (or "fat", as others have said)
vs. thin here since in the realm of registries these terms are already occupied.
I think the validation is related to, but otherwise independent of the type
of object passed.
In your scenario any DNSKEY that would end up in the registry db would have
to be present at the apex at the time of registration, which prohibits
pre-publication of a DS RR for a DNSKEY not yet present at the apex DNSKEY RRSet.

I don't understand how the DNSKEY would be worse for the registrant than the DS given that
the DNSKEY is what they already have in their hands.

-Peter
_______________________________________________
provreg mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/provreg
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.