[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]


To: Edward Lewis <edlewis@arin.net>
Cc: Michael Richardson <mcr@sandelman.ottawa.on.ca>, dnsop@cafax.se
From: George Michaelson <ggm@apnic.net>
Date: Thu, 20 Mar 2003 05:12:00 +1000
In-Reply-To: <a05111b1eba9e6e469f6e@[130.129.133.242]>
Sender: owner-dnsop@cafax.se
Subject: Re: Radical Surgery proposal: stop doing reverse for IPv6.


As another comment here, about the only thing you can take from the DNS is the
->name<- of a key, if the use is to be applied outside of DNS as data in
itself. This came up in PKIX, and got sat on pretty quick.

Unless I mis-read the Security directorate black hat view, its not permissable
to use DNSSEC keys to secure any other aspect of the Internet, apart from the
DNS itself. 

So we'd be talking about an RR identifying a key, to be found in some other
context specific key distribution framework. Right?

-george
#----------------------------------------------------------------------
# To unsubscribe, send a message to <dnsop-request@cafax.se>.

Home | Date list | Subject list