Re: [DNSOP] I-D Action: draft-ietf-dnsop-dnssec-key-timing-05.txt

2014-10-04 Thread Paul Hoffman
Greetings again. I just discovered a reference nit, but one that might cause consternation for someone reading the document. 5. Algorithm Considerations The preceding sections have implicitly assumed that all keys and (section 2.4) requires that there be an RRSIG for each RRset using at

Re: [DNSOP] I-D Action: draft-ietf-dnsop-dnssec-key-timing-05.txt

2014-09-25 Thread Paul Hoffman
On Sep 25, 2014, at 5:38 AM, Stephen Morris wrote: >> In 2.2, it says "It is important to note that this does not >> preclude the development of key rollover logic"; I can't figure >> out what "this" refers to. There are a bunch of things in the two >> preceding paragraphs that it might mean. >

Re: [DNSOP] I-D Action: draft-ietf-dnsop-dnssec-key-timing-05.txt

2014-09-25 Thread Stephen Morris
Paul Thanks for taking the time to go through the draft. Addressing your comments: On 23/09/14 04:06, Paul Hoffman wrote: > At the beginning of 2.1: For ZSKs, the issue for the zone > operator/signer is to ensure that any caching validator has access > to a particular signature that correspond

Re: [DNSOP] I-D Action: draft-ietf-dnsop-dnssec-key-timing-05.txt

2014-09-23 Thread Niall O'Reilly
At Tue, 23 Sep 2014 08:51:26 -0700, Paul Hoffman wrote: > > Does the following help? > > For ZSKs, the issue for the zone operator/signer is to ensure that > any caching validator has access to a particular signature also has > access to the corresponding valid ZSK. After reading the alt

Re: [DNSOP] I-D Action: draft-ietf-dnsop-dnssec-key-timing-05.txt

2014-09-23 Thread Paul Hoffman
On Sep 23, 2014, at 8:42 AM, Niall O'Reilly wrote: > At Mon, 22 Sep 2014 20:06:06 -0700, > Paul Hoffman wrote: >> >> I did a clean read, and it feels *much* better than the early drafts. I have >> a small number of editorial comments, but some bigger questions as well. I >> strongly suspect th

Re: [DNSOP] I-D Action: draft-ietf-dnsop-dnssec-key-timing-05.txt

2014-09-23 Thread Niall O'Reilly
At Mon, 22 Sep 2014 20:06:06 -0700, Paul Hoffman wrote: > > I did a clean read, and it feels *much* better than the early drafts. I have > a small number of editorial comments, but some bigger questions as well. I > strongly suspect the questions can be answered by small additions to the > draf

Re: [DNSOP] I-D Action: draft-ietf-dnsop-dnssec-key-timing-05.txt

2014-09-22 Thread Paul Hoffman
On Sep 18, 2014, at 11:51 AM, Tim Wicinski wrote: > This document has been in WGLC and the working group has done an iteration on > the document. The authors merged in several sets of changes, first back in > July, and recently from the feedback from the working group reviewers and > editors.

[DNSOP] I-D Action: draft-ietf-dnsop-dnssec-key-timing-05.txt

2014-09-17 Thread internet-drafts
A New Internet-Draft is available from the on-line Internet-Drafts directories. This draft is a work item of the Domain Name System Operations Working Group of the IETF. Title : DNSSEC Key Rollover Timing Considerations Authors : Stephen Morris