To:
Miek Gieben <miekg@atoom.net>
Cc:
dnsop <dnsop@cafax.se>
From:
Edward Lewis <edlewis@arin.net>
Date:
Tue, 1 Apr 2003 09:41:55 -0500
In-Reply-To:
<20030331132915.GA2912@atoom.net>
Sender:
owner-dnsop@cafax.se
Subject:
Re: preconfigured keys or ds's
I really think this is an implementation-by-implementation decision. At best, an information RFC describing your experiences in developing running code. At 15:29 +0200 3/31/03, Miek Gieben wrote: >Hello, > >I would like to see the following documented, but I don't know for sure >if it is a dnssec or dnsop issue: > >The preconfigured keys for resolvers are large and are hard to compare >and read (by humans). DS records on the other hand are much smaller >and easier to handle. I think it would be better to preconfigure >DS records in stead of zone keys for resolvers. This is also how >my perl resolver works. > >Where to put this? In the dnssec drafts or in a seperate dnsop BCP? > >grtz Miek -- -=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=- Edward Lewis +1-703-227-9854 ARIN Research Engineer I've had it with world domination. The maintenance fees are too high. #---------------------------------------------------------------------- # To unsubscribe, send a message to <dnsop-request@cafax.se>.