> [Allowing the child to send both DS and DNSKEY] adds some > complexity. Is the benefit worth it or not?
Yes. The hash function (digest) field in the DS record can be used for signaling, so the child should have some way of specifying the DS hash algorithm. Allowing the child to specify the entire DS record seems more sensible than adding a digest data element to the EPP key spec. An example: draft-ietf-dnsext-dnssec-trans-01.txt talks about using algorithm numbers for signaling a protocol change in the child zone. DS hash algorithm numbers could be used in the same way. This is perhaps not very wise, but it may well work. -- Sam . dnsop resources:_____________________________________________________ web user interface: http://darkwing.uoregon.edu/~llynch/dnsop.html mhonarc archive: http://darkwing.uoregon.edu/~llynch/dnsop/index.html
