On Sep 8, 2006, at 7:32 PM, Paul Vixie wrote:

[EMAIL PROTECTED] (Roy Arends) writes:

This is not the case for RIPE (194.in-addr.arpa). RIPE uses e=3 for
both ZSK and KSK. Hence an emergency trust anchor roll is needed.

i'd argue that if 194.in-addr.arpa is not registered a DLV registry
and
if in-addr.arpa is not itself signed, then the community of
beneficiaries
of 194's signedness is so small that this cannot be called an
emergency.

I wouldn't use a dlv registry. All dlv.isc.org's DNSKEYs have e=3.

;)

Roy
.
dnsop resources:_____________________________________________________
web user interface: http://darkwing.uoregon.edu/~llynch/dnsop.html
mhonarc archive: http://darkwing.uoregon.edu/~llynch/dnsop/index.html

Reply via email to