[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]


To: Antoin Verschuren <averschuren@vianetworks.nl>
Cc: ietf-provreg@cafax.se, Patrick <patrick@gandi.net>
From: Edward Lewis <lewis@tislabs.com>
Date: Thu, 23 Aug 2001 10:22:43 -0400
In-Reply-To: <Pine.BSF.4.10.10108231322540.99081-100000@surf.iae.nl>
Sender: owner-ietf-provreg@cafax.se
Subject: Re: host transfers -- actually, out-of-zone-glue

At 8:35 AM -0400 8/23/01, Antoin Verschuren wrote:
>I also wonder how registration of nameservers will take place in the
>future with DNSsec. As far as I can tell, this will probably make it
>nessecary that the maintainer of the host record is indeed the owner of
>the actual nameserver, because he will have to be able to access the
>nameserver and negociate the encryption keys.

Speaking as someone who has spent years on DNSSEC (and not as a WG chair):
Neither the NS set nor glue records are signed, hence DNSSEC doesn't play a
role in name server data.  DNSSEC will impact delegations, but quite
frankly, how DNSSEC will is being reviewed in the DNSEXT and DNSOP WGs.

-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=--=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
Edward Lewis                                                NAI Labs
Phone: +1 443-259-2352                      Email: lewis@tislabs.com

You fly too often when ... the airport taxi is on speed-dial.

Opinions expressed are property of my evil twin, not my employer.



Home | Date list | Subject list