> > > > - The parent is already trusted with DNSSEC tools, since the parent is
> > > > signing the parent's zone (including the DS record!)
> > >
> > > assuming facts not in evidence. there is active discussion
> > > about having unsigned zones w/ DS records included.
> >
> > Well you are not talking about DNSSEC 4035 then. Such DS
> > records are just noise to DNSSEC 4035.
>
> Well, i never said I was talking abt DNSSEC 4035. (what is that
> anyway? DNSSEC as defiend by RFC 4035?)
Yes.
> I was talking about
> who generates DS rr's. Brian postualates the parent is always
> ready and willing to do so, I disagree, based on empirical
> evidence.
So do I. See my other posts.
Mark
> --bill
>
> > Mark
> > --
> > Mark Andrews, ISC
> > 1 Seymour St., Dundas Valley, NSW 2117, Australia
> > PHONE: +61 2 9871 4742 INTERNET: [EMAIL PROTECTED]
> _______________________________________________
> DNSOP mailing list
> [email protected]
> https://www.ietf.org/mailman/listinfo/dnsop
--
Mark Andrews, ISC
1 Seymour St., Dundas Valley, NSW 2117, Australia
PHONE: +61 2 9871 4742 INTERNET: [EMAIL PROTECTED]
_______________________________________________
DNSOP mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/dnsop