[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]


To: Olafur Gudmundsson <ogud@ogud.com>
Cc: namedroppers@ops.ietf.org, dnssec@cafax.se
From: Roy Arends <Roy.Arends@nominum.com>
Date: Sat, 9 Jun 2001 23:12:49 +0200 (CEST)
Delivery-Date: Sun Jun 10 05:30:26 2001
Sender: owner-dnssec@cafax.se
Subject: DK RR & Child's secure status

Hi,

When the DK record is used to indicate the KEY which the child uses to
sign its apex KEY RRset, a child _zone_ might or might not be signed.

This breaks the secure delegation scheme as the parent has no way of
indicating if it considers a child zone secure or not.

At least, if I understood the draft right.

Regards

Roy Arends
Nominum









Home | Date list | Subject list