W dniu 07.07.2019 o 00:39, Joe Abley pisze:
> What's the use-case for using the DNS to transfer private key data?All of 
> those methods require configuring an external, out-of-band
mechanism to transfer the ZSK - using covert records is something that'd
work 'out of the box'.
The primary use case I'm thinking about is to give secondaries the
ability to do online NSEC signing to provide white lies. Proposed NSEC5
also requires a method to transfer the private key to the slave.
And, again - this is just one of the proposed uses of covert RRs, this
document is showing it just as an example.
-- 
Witold

_______________________________________________
DNSOP mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/dnsop

Reply via email to