> [Allowing the child to send both DS and DNSKEY] adds some
> complexity.  Is the benefit worth it or not?

Yes.

The hash function (digest) field in the DS record can be used for
signaling, so the child should have some way of specifying the DS hash
algorithm.  Allowing the child to specify the entire DS record seems
more sensible than adding a digest data element to the EPP key spec.

An example: draft-ietf-dnsext-dnssec-trans-01.txt talks about using
algorithm numbers for signaling a protocol change in the child zone.
DS hash algorithm numbers could be used in the same way.  This is
perhaps not very wise, but it may well work.

-- Sam
.
dnsop resources:_____________________________________________________
web user interface: http://darkwing.uoregon.edu/~llynch/dnsop.html
mhonarc archive: http://darkwing.uoregon.edu/~llynch/dnsop/index.html

Reply via email to