Russ Housley <hous...@vigilsec.com> writes:

> It is a good time to do rfc5011-bis.  Real world experience from the
> KSK roll makes a lot os sense to me.

I think step one would be to list the aspects of it that worked well,
and the aspects that didn't.  From that we can determine the need for a
replacement and what features would be needed in order to accommodate the
aspects that didn't work well.  I do believe it worked quite well over
all, but there are elements that were lacking and may be worth doing a
bis to address.  [but we really need a upsides-and-downsides list based
on experience first in order to evaluate the need to do a bis].
-- 
Wes Hardaker
USC/ISI

_______________________________________________
DNSOP mailing list
DNSOP@ietf.org
https://www.ietf.org/mailman/listinfo/dnsop

Reply via email to