To:
Dan Massey <masseyd@isi.edu>
Cc:
dnssec@cafax.se
From:
Miek Gieben <miekg@nlnetlabs.nl>
Date:
Wed, 18 Apr 2001 16:01:58 +0200
Delivery-Date:
Thu Apr 19 20:30:44 2001
In-Reply-To:
<20010418090117.A2105@snarl.east.isi.edu>; from masseyd@isi.edu on Wed, Apr 18, 2001 at 09:01:17AM -0400
Sender:
owner-dnssec@cafax.se
Subject:
Re: Keys at apex problem
On Wed, Apr 18, 2001 at 09:01:17AM -0400, Dan Massey wrote: > Hi, > > Looking back on the namedroppers discussion, it seemed like the > consensus was that non-zone keys shouldn't be present at the > apex (I agree) and that this problem could be resolved by adding > a SHOULD to the spec (I don't agree). How do you see it then? As a must? I'm playing with the idea to mention this some more in the draft, like: If KEYS other than zone KEYS or not placed in the apex of a zone then they SHOULD/MUST (?) be placed in the seperate child zone, called keys.zone. ...but it like to have some more input on this. grtz Miek