[On 11 Nov, @ 17:14, Ben wrote in "Re: [dnsop] Comments on key ro ..."] > > o ZSK rollovers are easy to automate as only the local zone is > > involved. > > o A KSK rollover needs interaction between the parent and child. > > Data exchange is needed to provide the new keys to the parent, > > consequently, this data must be authenticated and integrity must > > be guaranteed in order to avoid attacks on the rollover. > > o All time and TTL considerations presented in Section 3.3 apply to > > an automated rollover. > > > >which in my mind sums it all up, so I would favor dropping the key req. > >draft, > > This doesn't say anything about SEP keys, though.
it talks about ksk keys, which are implied to be sep keys (that is defined somewhere else in the doc) grtz Miek . dnsop resources:_____________________________________________________ web user interface: http://darkwing.uoregon.edu/~llynch/dnsop.html mhonarc archive: http://darkwing.uoregon.edu/~llynch/dnsop/index.html
