Miek Gieben wrote:
[On 09 Nov, @ 21:51, Samuel wrote in "[dnsop] Comments on key rollov ..."]
This document has a number of unjustified and mutually exclusive
requirements. To wit:
in the dnssec-operational draft, we have the following:
3.3.4 Automated Key Rollovers
As keys must be renewed periodically, there are some motivation to
automate the rollover process (also see [12])
o ZSK rollovers are easy to automate as only the local zone is
involved.
o A KSK rollover needs interaction between the parent and child.
Data exchange is needed to provide the new keys to the parent,
consequently, this data must be authenticated and integrity must
be guaranteed in order to avoid attacks on the rollover.
o All time and TTL considerations presented in Section 3.3 apply to
an automated rollover.
which in my mind sums it all up, so I would favor dropping the key req.
draft,
This doesn't say anything about SEP keys, though.
Cheers,
Ben.
.
dnsop resources:_____________________________________________________
web user interface: http://darkwing.uoregon.edu/~llynch/dnsop.html
mhonarc archive: http://darkwing.uoregon.edu/~llynch/dnsop/index.html