Hello,

 In the draft draft-ietf-dnsop-key-rollover-requirements-01.txt
 we define requirements for automated key rollover between parent and
 child zones.

 In section 4, we propose to use only DNSSEC mechanisms to secure
 exchanged data between parent and child zones. Recent
 comments from Olaf suggest to use another mechanism.

 I think the first question is:
 Do the requirements include the choice of the mechanism used
 to secure key exchanged between parent and child zones?

 If the answer is yes, there are several choices:

 DNSSEC only: motivation to use only DNSSEC mechanism is to keep
 the automatic key rollover process independant from other protocol.

 Using IPsec to secure communications.
 Using EPP.
 ...

 We think that comments and discussions about this point are needed to
 enlightened pros and cons of each choice.

 Regards



.
dnsop resources:_____________________________________________________
web user interface: http://darkwing.uoregon.edu/~llynch/dnsop.html
mhonarc archive: http://darkwing.uoregon.edu/~llynch/dnsop/index.html

Reply via email to