W dniu 07.07.2019 o 00:39, Joe Abley pisze: > What's the use-case for using the DNS to transfer private key data?All of > those methods require configuring an external, out-of-band mechanism to transfer the ZSK - using covert records is something that'd work 'out of the box'. The primary use case I'm thinking about is to give secondaries the ability to do online NSEC signing to provide white lies. Proposed NSEC5 also requires a method to transfer the private key to the slave. And, again - this is just one of the proposed uses of covert RRs, this document is showing it just as an example. -- Witold
_______________________________________________ DNSOP mailing list [email protected] https://www.ietf.org/mailman/listinfo/dnsop
