Miek Gieben wrote:
[On 11 Nov, @ 17:14, Ben wrote in "Re: [dnsop] Comments on key ro ..."]
o ZSK rollovers are easy to automate as only the local zone is
involved.
o A KSK rollover needs interaction between the parent and child.
Data exchange is needed to provide the new keys to the parent,
consequently, this data must be authenticated and integrity must
be guaranteed in order to avoid attacks on the rollover.
o All time and TTL considerations presented in Section 3.3 apply to
an automated rollover.
which in my mind sums it all up, so I would favor dropping the key req.
draft,
This doesn't say anything about SEP keys, though.
it talks about ksk keys, which are implied to be sep keys (that is
defined somewhere else in the doc)
SEP keys do not have a parent!
.
dnsop resources:_____________________________________________________
web user interface: http://darkwing.uoregon.edu/~llynch/dnsop.html
mhonarc archive: http://darkwing.uoregon.edu/~llynch/dnsop/index.html