As mentioned in the WG meeting: Looking back on the RFC2541 draft, it mostly deals with key generation and lifetime requirements. draft-ietf-dnsop-dnssec-operational-practices-02 covers much more ground with operation procedures for key rollovers.
RFC 2541 also gives hard numbers for key length minimums and lifetimes, which may not always hold in different deployments. For example: Transaction security keys have a suggesed max lifetime of 36 days. It also only addresses RSA/MD5 which is now not recommeded for DNSSEC. So while a initial document for DNSSEC deployment, it does not address several key items in maintaining a secure tree. I would therefore like to see the new draft obsolete RFC2541 and progress as an informational RFC. Scott . dnsop resources:_____________________________________________________ web user interface: http://darkwing.uoregon.edu/~llynch/dnsop.html mhonarc archive: http://darkwing.uoregon.edu/~llynch/dnsop/index.html
