[Fwd: Outdated RIPE NCC Trust Anchors in Fedora Linux Repositories]

2010-02-05 Thread Alan Clegg
I find this important enough to forward on to bind-users. Please not the importance of trust anchor management. AlanC ---BeginMessage--- [Apologies for duplicates] Dear Colleagues, We have discovered that recent versions of the Fedora Linux distribution are shipping with a package called

Re: [Fwd: Outdated RIPE NCC Trust Anchors in Fedora Linux Repositories]

2010-02-05 Thread Adam Tkac
On Fri, Feb 05, 2010 at 06:22:26AM -0800, Alan Clegg wrote: I find this important enough to forward on to bind-users. Please not the importance of trust anchor management. We (= me and Paul Wouters) are working on dnssec-conf update. Sorry for troubles. Regards, Adam Date: Fri, 05 Feb 2010

Re: [Fwd: Outdated RIPE NCC Trust Anchors in Fedora Linux Repositories]

2010-02-05 Thread Mark Andrews
In message 20100205143439.ga15...@evileye.atkac.englab.brq.redhat.com, Adam T kac writes: On Fri, Feb 05, 2010 at 06:22:26AM -0800, Alan Clegg wrote: I find this important enough to forward on to bind-users. Please not the importance of trust anchor management. We (= me and Paul

Re: [Fwd: Outdated RIPE NCC Trust Anchors in Fedora Linux Repositories]

2010-02-05 Thread Paul Wouters
On Sat, 6 Feb 2010, Mark Andrews wrote: We (= me and Paul Wouters) are working on dnssec-conf update. Sorry for troubles. The better thing would be a a script to fetch the current keys nightly, perform a sanity check, then update or inform the administator and let them update the keys after

Re: [Fwd: Outdated RIPE NCC Trust Anchors in Fedora Linux Repositories]

2010-02-05 Thread Alan Clegg
Paul Wouters wrote: With the current success of the DLV, and the root zone deployment half a year away, it is not really required anymore. I think it is much better to get rid of all trust anchors apart from the ISC DLV key. Do remember, however, that the DLV keys also roll, so this does need