Re: DNSSEC submit of DLV vs DNSKEY records?

2011-05-09 Thread Stephane Bortzmeyer
On Fri, May 06, 2011 at 12:45:17PM +1000, Mark Andrews wrote a message of 52 lines which said: > Once the parent zone is signed and is accepting DS/DNSKEY records "is accepting" is not sufficient. Many TLD are managed in a strict registry/registrar fashion which means that it is not enough f

Re: DNSSEC submit of DLV vs DNSKEY records?

2011-05-06 Thread Chris Thompson
On May 6 2011, Mark Andrews wrote: Once the parent zone is signed and is accepting DS/DNSKEY records for child zones there shouldn't be any need to add records to DLV. Well, for some value of "should" ... It might be that the parent, although signed and accepting DS records, does not yet have

Re: DNSSEC submit of DLV vs DNSKEY records?

2011-05-05 Thread
On Fri, 06 May 2011 12:45 +1000, "Mark Andrews" wrote: > > > [I hope someone will correct me if I'm wrong.] > > > > > > My understanding: if the parent is signed, that is the only way a > > > child zone can be validated, unless of course using trusted-keys. > > > DLV is only done when the paren

Re: DNSSEC submit of DLV vs DNSKEY records?

2011-05-05 Thread Mark Andrews
In message <1304628473.25384.1448737...@webmail.messagingengine.com>, dchilton+ b...@bestmail.us writes: > "missed it by THAT much ...". thx! relocating to bind-users. > > On Thu, 05 May 2011 14:37 -0500, "/dev/rob0" wrote: > > FWIW I think you hit the wrong list. Did you mean bind-users@isc? >

Re: DNSSEC submit of DLV vs DNSKEY records?

2011-05-05 Thread Torinthiel
On 05/05/11 22:47, dchilton+b...@bestmail.us wrote: > "missed it by THAT much ...". thx! relocating to bind-users. > > On Thu, 05 May 2011 14:37 -0500, "/dev/rob0" wrote: >> FWIW I think you hit the wrong list. Did you mean bind-users@isc? > > >> On Thu, May 05, 2011 at 12:25:27PM -0700, dchil

Re: DNSSEC submit of DLV vs DNSKEY records?

2011-05-05 Thread dchilton+bind
"missed it by THAT much ...". thx! relocating to bind-users. On Thu, 05 May 2011 14:37 -0500, "/dev/rob0" wrote: > FWIW I think you hit the wrong list. Did you mean bind-users@isc? > On Thu, May 05, 2011 at 12:25:27PM -0700, dchilton+b...@bestmail.us >wrote: > > after signing my zones wit