On 3 Apr 2013, at 16:11, Paul Wouters <p...@nohats.ca> wrote: > It's the vendors of equipment supporting DNSSEC that have > the real issues. If they shipped with a root anchor, and their stuff > is offline for 5 years and turned on, their DNS will be broken and 5011 > isn't going to be useful to them.....
The real problem occurs when the latest release of the validator software was published before the rollover, and you install it after the rollover. It is perfectly reasonable to install software that is a few months old. Tony. -- f.anthony.n.finch <d...@dotat.at> http://dotat.at/ _______________________________________________ DNSOP mailing list DNSOP@ietf.org https://www.ietf.org/mailman/listinfo/dnsop