David Conrad wrote: >> The IPv6 net has decreed “No, really, FRAGMENTS DO NOT WORK”. > > This could be a bit of an issue when the DNSSEC root key is rolled.
It is not, if separate RR types are used for different set of authentication algorithms and, during roll over, separate RR types are used for the current most and the second (and third or more, if necessary) current information, as I mentioned decades ago. Masataka Ohta _______________________________________________ DNSOP mailing list DNSOP@ietf.org https://www.ietf.org/mailman/listinfo/dnsop