Adam D. Barratt wrote: > Hi, > > It's not clear whether there will have been a stretch point release > before the KSK rollover in October, but there definitely won't have > been a jessie point release, and in any case we need to update unbound > in the next couple of days (to avoid new installs on stretch having > broken DNSSEC validation for the next month). > > Assuming I've not missed any packages that have been updated, we need > four SUAs. I've included draft text for each below - review, comments > and suggestions welcome.
Hi, Adam: Thanks for writing these! The text mostly looks good to me. The only nit I have is that I would write "The keys used to authenticate the root DNS zone" instead of "The keys used to [sign] the root DNS zone[s]". Technically, there is a chain of signatures and the KSKs do not directly sign the root zone, and there is only a singular root zone. -- Robert Edmonds [email protected]

