On Sun, Jul 25, 2010 at 10:39:15PM +0200, hsalg...@nic.cl wrote:
>> My concern is whether this draft is the right place for such text.
>> The IANA process is a special case and is not concerned with the
>> timing issues that are the focus of the document; as such, it may
>> belong more in
Quoting Stephen Morris :
On 9 Jul 2010, at 20:41, Hugo Salgado wrote:
But with the Double-signature method, besides the two KSK DNSKEY
records, you need two *RRSIG* records, one with each KSK.
I think the Double-DS method still fits in the process of IANA,
if we take care that in the child y
On 9 Jul 2010, at 20:41, Hugo Salgado wrote:
>> But with the Double-signature method, besides the two KSK DNSKEY
>> records, you need two *RRSIG* records, one with each KSK.
>>
>> I think the Double-DS method still fits in the process of IANA,
>> if we take care that in the child you'll nedd to
On 07/09/2010 03:32 PM, Hugo Salgado wrote:
> On 07/07/2010 04:52 AM, Stephen Morris wrote:
>> On 15 Jun 2010, at 14:49, Hugo Salgado Hernandez wrote:
>>
>>> I have a comment regarding the KSK rollover with the "Double-DS" method,
>>> section 3.3.2.
>>>
>>> The ICANN draft procedure for submitting
On 07/07/2010 04:52 AM, Stephen Morris wrote:
> On 15 Jun 2010, at 14:49, Hugo Salgado Hernandez wrote:
>
>> I have a comment regarding the KSK rollover with the "Double-DS" method,
>> section 3.3.2.
>>
>> The ICANN draft procedure for submitting DS to the root zone require
>> that:
>> "At the t
On 15 Jun 2010, at 14:49, Hugo Salgado Hernandez wrote:
> I have a comment regarding the KSK rollover with the "Double-DS" method,
> section 3.3.2.
>
> The ICANN draft procedure for submitting DS to the root zone require
> that:
> "At the time of the trust anchor request, there must be a DNSKEY
I have a comment regarding the KSK rollover with the "Double-DS" method,
section 3.3.2.
The ICANN draft procedure for submitting DS to the root zone require
that:
"At the time of the trust anchor request, there must be a DNSKEY that
matches the DS record present in the child zone. This will
A new version of the DNSSEC key timing draft has been submitted. Amongst
the changes, timings for additional KSK and ZSK rollover methods have been
included following feedback from the IETF meeting in Hiroshima.
> A new version of I-D, draft-morris-dnsop-dnssec-key-timing-02.txt has
been
> su