On 22 Jul 2008, at 23:49, Kevin Oberman wrote:

Someone needs to write a really good tutorial on dnssec. The bits and pieces are scattered about the web, but explanations of now to publish
your keys, to whom they need to be published and what is involved in
the ongoing maintenance are lacking.  Especially a clear explanation
of what is required to run both keyed and "legacy" dns at the same

Another piece of text can be found at


I can't imagine why anyone would want to run both. Resolvers which don't
know how to check signatures simple don't do so and everything still

A pretty good, though somewhat outdated tutorial can be found in NIST
SP800-81. It's pretty readable and tells you how to generate keys and
sign a zone properly.


Attachment: PGP.sig
Description: This is a digitally signed message part

Reply via email to