[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [dnsext] Trust Anchors



the operational problem here is, again, that resolver operators don't necessarily sync-up with zone producers.

I also think that closest should be the way to go when you have 2 or more keys that can validate a given signature.

Given this is an operational problem, I believe tweaking the protocol will never yield a perfect solution and that this sort of situation would see the users better served by crafting a BCP where, for instance, the choreography necessary for domain moves between registrars would be listed. The situation when a parent zone becomes DNSSEC enabled (allowing DS records to be stored there and signed) might lead to an operational recommendation for the child zone producer to keep the keys unchanged from the time when the zone was an island, that is: do not roll just because your parent became DNSSEC-enabled.

Joao