Re: dnskey algorithm update

2016-01-08 Thread Casey Deccio
On Thu, Jan 7, 2016 at 3:00 PM, Carl Byington wrote: > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA512 > > On Thu, 2016-01-07 at 08:34 -0600, Jeremy C. Reed wrote: > > On Wed, 6 Jan 2016, Carl Byington wrote: > > > > Is there a more authoritative document that describes the

Re: dnskey algorithm update

2016-01-06 Thread Jay Ford
On Wed, 6 Jan 2016, Carl Byington wrote: My zones are currently using algorithm 5 (RSASHA1), with two KSKs and two ZSKs with overlapping timers. In preparation for updating to algorithm 8 (RSASHA256), I read: The bind-users thread "KSK signing all records; NSEC3 algorithm status?"