Re: NSD and DNSSEC signature refreshing and ZSK rotation

Paul Wouters <[email protected]>
Newsgroups gmane.network.dns.nsd.general
Message-ID <[email protected]>
> On Feb 15, 2018, at 12:23, Michael A. Peters <[email protected]> wrote:



> ZSK is easy but ZSK should be 1024-bit to keep DNS responses small,

There is no proof this is needed or required.

And strong reasons to not use 1024 RSA anymore. The root ZSK is now 2048 with no issues reported.

Paul
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.