To:
Olafur Gudmundsson <ogud@ogud.com>
Cc:
namedroppers@ops.ietf.org, dnssec@cafax.se
From:
Roy Arends <Roy.Arends@nominum.com>
Date:
Sat, 9 Jun 2001 23:12:49 +0200 (CEST)
Delivery-Date:
Sun Jun 10 05:30:26 2001
Sender:
owner-dnssec@cafax.se
Subject:
DK RR & Child's secure status
Hi, When the DK record is used to indicate the KEY which the child uses to sign its apex KEY RRset, a child _zone_ might or might not be signed. This breaks the secure delegation scheme as the parent has no way of indicating if it considers a child zone secure or not. At least, if I understood the draft right. Regards Roy Arends Nominum