Re: DNSSEC DS record generation for DOT-US from NSEC3 signed-zone

2010-08-15 Thread Mark Andrews
In message <4c67047a.3020...@jason.roysdon.net>, Jason Roysdon writes: > > On 08/14/2010 12:43 AM, Matthew Seaman wrote: > > On 14/08/2010 02:08, Jason Roysdon wrote: > >> The problem I have is that my zone is using an NSEC3 and when BIND's > >> dnssec-signzone generates dsset files, it does so w

Re: DNSSEC DS record generation for DOT-US from NSEC3 signed-zone

2010-08-14 Thread Jason Roysdon
On 08/14/2010 12:43 AM, Matthew Seaman wrote: > On 14/08/2010 02:08, Jason Roysdon wrote: >> The problem I have is that my zone is using an NSEC3 and when BIND's >> dnssec-signzone generates dsset files, it does so with algorithm 7. How >> can I generate DS records with NSEC3 keys, for algorithm

DNSSEC DS record generation for DOT-US from NSEC3 signed-zone

2010-08-13 Thread Jason Roysdon
I am working on getting my DS record added to the DOT-US zone with Neustar. In doing so, I found out they have a limitation of only supporting algorithm 3, which is DSA/SHA1, or algorithm 5, which is RSA/SHA1: http://www.iana.org/assignments/dns-sec-alg-numbers/dns-sec-alg-numbers.xhtml They do n