Miek Gieben wrote:
[On 11 Nov, @ 17:14, Ben wrote in "Re: [dnsop] Comments on key ro ..."]

 o  ZSK rollovers are easy to automate as only the local zone is
    involved.
 o  A KSK rollover needs interaction between the parent and child.
    Data exchange is needed to provide the new keys to the parent,
    consequently, this data must be authenticated and integrity must
    be guaranteed in order to avoid attacks on the rollover.
 o  All time and TTL considerations presented in Section 3.3 apply to
    an automated rollover.

which in my mind sums it all up, so I would favor dropping the key req.
draft,

This doesn't say anything about SEP keys, though.


it talks about ksk keys, which are implied to be sep keys (that is
defined somewhere else in the doc)

SEP keys do not have a parent! . dnsop resources:_____________________________________________________ web user interface: http://darkwing.uoregon.edu/~llynch/dnsop.html mhonarc archive: http://darkwing.uoregon.edu/~llynch/dnsop/index.html

Reply via email to