"Michael J. Sheldon" <[email protected]> writes:

Brian and Michael both,

> > Rationale : the current text seems to imply this code is only when
> > there is no DNSKEY at all.

>  I disagree. There are going to be cases where DS and DNSKEY are not
> fully in sync due to key rollovers, prestaging, etc. This is not a fatal
> error.

[and Brian agreed elsewhere]

Thanks for your comments on the draft and this discussion.  You can read
the results of this particular point in my response to Petr under bullet
6.4 in that message.
-- 
Wes Hardaker
USC/ISI

_______________________________________________
DNSOP mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/dnsop

Reply via email to