On Fri, Aug 29, 2008 at 10:23:53AM +1000, Mark Andrews wrote:
>
> > > - The parent is already trusted with DNSSEC tools, since the parent is
> > > signing the parent's zone (including the DS record!)
> >
> > assuming facts not in evidence. there is active discussion
> > about having unsigned zones w/ DS records included.
>
> Well you are not talking about DNSSEC 4035 then. Such DS
> records are just noise to DNSSEC 4035.
Well, i never said I was talking abt DNSSEC 4035. (what is that
anyway? DNSSEC as defiend by RFC 4035?) I was talking about
who generates DS rr's. Brian postualates the parent is always
ready and willing to do so, I disagree, based on empirical
evidence.
--bill
> Mark
> --
> Mark Andrews, ISC
> 1 Seymour St., Dundas Valley, NSW 2117, Australia
> PHONE: +61 2 9871 4742 INTERNET: [EMAIL PROTECTED]
_______________________________________________
DNSOP mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/dnsop