[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: [dnsext] Trust Anchors
the operational problem here is, again, that resolver operators don't
necessarily sync-up with zone producers.
I also think that closest should be the way to go when you have 2 or
more keys that can validate a given signature.
Given this is an operational problem, I believe tweaking the protocol
will never yield a perfect solution and that this sort of situation
would see the users better served by crafting a BCP where, for
instance, the choreography necessary for domain moves between
registrars would be listed.
The situation when a parent zone becomes DNSSEC enabled (allowing DS
records to be stored there and signed) might lead to an operational
recommendation for the child zone producer to keep the keys unchanged
from the time when the zone was an island, that is: do not roll just
because your parent became DNSSEC-enabled.
Joao