> > > > - The parent is already trusted with DNSSEC tools, since the parent is 
> > > > signing the parent's zone (including the DS record!)
> > > 
> > >   assuming facts not in evidence. there is active discussion 
> > >   about having unsigned zones w/ DS records included.
> > 
> >     Well you are not talking about DNSSEC 4035 then.  Such DS
> >     records are just noise to DNSSEC 4035.
> 
>       Well, i never said I was talking abt DNSSEC 4035. (what is that
>       anyway?  DNSSEC as defiend by RFC 4035?)

        Yes.  

>       I was talking about 
>       who generates DS rr's.  Brian postualates the parent is always
>       ready and willing to do so, I disagree, based on empirical 
>       evidence.

        So do I.  See my other posts.

        Mark

> --bill
> 
> >     Mark
> > -- 
> > Mark Andrews, ISC
> > 1 Seymour St., Dundas Valley, NSW 2117, Australia
> > PHONE: +61 2 9871 4742                 INTERNET: [EMAIL PROTECTED]
> _______________________________________________
> DNSOP mailing list
> DNSOP@ietf.org
> https://www.ietf.org/mailman/listinfo/dnsop
-- 
Mark Andrews, ISC
1 Seymour St., Dundas Valley, NSW 2117, Australia
PHONE: +61 2 9871 4742                 INTERNET: [EMAIL PROTECTED]
_______________________________________________
DNSOP mailing list
DNSOP@ietf.org
https://www.ietf.org/mailman/listinfo/dnsop

Reply via email to