As mentioned in the WG meeting:  Looking back on the RFC2541 draft, it
mostly deals with key generation and lifetime requirements.
draft-ietf-dnsop-dnssec-operational-practices-02 covers much more ground
with operation procedures for key rollovers.

RFC 2541 also gives hard numbers for key length minimums and lifetimes,
which may not always hold in different deployments.  For example:
Transaction security keys have a suggesed max lifetime of 36 days.  It also
only addresses RSA/MD5 which is now not recommeded for DNSSEC.  So while a
initial document for DNSSEC deployment, it does not address several key
items in maintaining a secure tree.

I would therefore like to see the new draft obsolete RFC2541 and progress as
an informational RFC.

Scott


.
dnsop resources:_____________________________________________________
web user interface: http://darkwing.uoregon.edu/~llynch/dnsop.html
mhonarc archive: http://darkwing.uoregon.edu/~llynch/dnsop/index.html

Reply via email to