On Fri, Aug 29, 2008 at 10:23:53AM +1000, Mark Andrews wrote: > > > > - The parent is already trusted with DNSSEC tools, since the parent is > > > signing the parent's zone (including the DS record!) > > > > assuming facts not in evidence. there is active discussion > > about having unsigned zones w/ DS records included. > > Well you are not talking about DNSSEC 4035 then. Such DS > records are just noise to DNSSEC 4035.
Well, i never said I was talking abt DNSSEC 4035. (what is that anyway? DNSSEC as defiend by RFC 4035?) I was talking about who generates DS rr's. Brian postualates the parent is always ready and willing to do so, I disagree, based on empirical evidence. --bill > Mark > -- > Mark Andrews, ISC > 1 Seymour St., Dundas Valley, NSW 2117, Australia > PHONE: +61 2 9871 4742 INTERNET: [EMAIL PROTECTED] _______________________________________________ DNSOP mailing list DNSOP@ietf.org https://www.ietf.org/mailman/listinfo/dnsop