|
Miek Gieben wrote: This draft is a requirement draft, thus the goal is to explicitely describe automated key rollover problems.[On 20 Jan, @ 09:07, Gilles wrote in "Re: [dnsop] I-D ACTION:draft-i ..."] We think that automated rollover is under treated in operationnal practice and some problems must be exposed. For example: Automated rollover parameters negociation between parent and child Possible manual changes during an automated rollover Key rollover process fault tolerance and consistent state of the chain of trust. Or more specifical: Direct query to authoritative name server avoiding recursive cache server. Concerning the protocol used to exchange data between parent and child, we agree that EPP can indeed be used. But, maybe other people want to use another protocol like DNSSEC, IPsec, ... That is why, we think this draft is enough original and pointed some problems not treated in other drafts or RFCs. Regards Regards, Miek -- Gilles Guette IRISA/INRIA Rennes France |
- [dnsop] I-D ACTION:draft-ietf-dnsop-key-rollover-requireme... Internet-Drafts
- Re: [dnsop] I-D ACTION:draft-ietf-dnsop-key-rollover-... Gilles Guette
- Re: [dnsop] I-D ACTION:draft-ietf-dnsop-key-rollo... Miek Gieben
- Re: [dnsop] I-D ACTION:draft-ietf-dnsop-key-r... Gilles Guette
- Re: [dnsop] I-D ACTION:draft-ietf-dnsop-key-rollo... Miek Gieben
