[DNSOP] RFC4641bis: Remarks on pre-publish key rollover and dynamic dns zones

2009-03-25 Thread Holger Zuleger
Dear WG, I've implemented parts from RFC4641 in an automated zone signing and key rollover tool. Currently I'm looking for extensions to use this tool for the rollover of keys on dynamic dns zones. In this context I think that section 4.2.1.1 "Pre-Publish Key Rollover" does not fulfill all the

Re: [DNSOP] More solicitation for feedback on dns64

2009-03-25 Thread Matthijs Mekking
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hi Andrew, Also following the dns64 discussion, I thought the real issue was if we had a security-aware validating stub that does not understand translation. The stub resolver sets the CD bit but has no clue of how to do the translation. Regarding th

[DNSOP] draft-ietf-dnsop-dnssec-trust-anchor-03

2009-03-25 Thread Alfred Hönes
Generally: Thumbs up for this version! However, one legacy nit has been left untouched. In Section 5, 2nd para: s/number trust anchors/number of trust anchors/! ^ (No new draft version needed, wait for opportunity to fix!) Kind regards, Alfred

Re: [DNSOP] More solicitation for feedback on dns64

2009-03-25 Thread Andrew Sullivan
On Wed, Mar 25, 2009 at 11:08:08AM -0700, Matthijs Mekking wrote: > Also following the dns64 discussion, I thought the real issue was if we > had a security-aware validating stub that does not understand > translation. The stub resolver sets the CD bit but has no clue of how to > do the translatio