At 9:35 -0500 11/15/04, Samuel Weiler wrote:
[Allowing the child to send both DS and DNSKEY] adds some
complexity. Is the benefit worth it or not?
Yes.
Why? (The rest is just commentary on the DS option...)
The hash function (digest) field in the DS record can be used for
signaling, so the child should have some way of specifying the DS hash
algorithm. Allowing the child to specify the entire DS record seems
more sensible than adding a digest data element to the EPP key spec.
What part of a DS RR's rdata is not in a secDNS:dsData element?
An example: draft-ietf-dnsext-dnssec-trans-01.txt talks about using
algorithm numbers for signaling a protocol change in the child zone.
DS hash algorithm numbers could be used in the same way. This is
perhaps not very wise, but it may well work.
Let's burn that bridge when we come to it.
--
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
Edward Lewis +1-571-434-5468
NeuStar
I would have been at the meeting, but I was busy raking the leaves from
the (now) empty non-terminals in my yard.
.
dnsop resources:_____________________________________________________
web user interface: http://darkwing.uoregon.edu/~llynch/dnsop.html
mhonarc archive: http://darkwing.uoregon.edu/~llynch/dnsop/index.html