Re: [DNSOP] automatic update of DS records

2010-03-03 Thread Tony Finch
On Wed, 3 Mar 2010, Jay Daley wrote: But my point is that in the absence of a similar automated mechanism for NS records we use cut and paste and it works fine No it doesn't. Delegations are frequently partially broken. It would be a wasted opportunity to automate DS maintenance without

Re: [DNSOP] automatic update of DS records

2010-03-03 Thread Tony Finch
On Tue, 2 Mar 2010, Edward Lewis wrote: If you want to just get the DS from the child's servers to the parent's machines, we already have queries/responses and can secure that with TSIG or SIG(0). What is there to solve? What are the traps and pitfalls? What are the timing requirements?

Re: [DNSOP] automatic update of DS records

2010-03-03 Thread Tony Finch
On Tue, 2 Mar 2010, Doug Barton wrote: Throwing in some more bullet points: 1. There MUST be an OOB (where the B is DNS) channel for initial zone configuration, contact info changes, etc. 2. This channel already exists for Registrant/Admin/Billing/Technical contact info, name servers, etc.

Re: [DNSOP] automatic update of DS records

2010-03-03 Thread Alfred Hönes
On Wed, Mar 03, 2010 at 11:28:36AM +0100, Jaap Akkerhuis wrote: Antoin says: So there's one more logical entity involved; most likely this way: jaap ___ did i miss something? Antoin sez that where? That's been me, in my

Re: [DNSOP] automatic update of DS records

2010-03-03 Thread Jay Daley
On 4/03/2010, at 8:50 AM, Stephan Lagerholm wrote: Correct, but I have a hard time seeing that the loosing registrar would be that helpful. It is more realistic to think that they could provide access to the private key for their hosted customer. And in that case the key can not be shared

Re: [DNSOP] automatic update of DS records

2010-03-03 Thread Jaap Akkerhuis
On Wed, Mar 03, 2010 at 11:28:36AM +0100, Jaap Akkerhuis wrote: Antoin says: So there's one more logical entity involved; most likely this way: jaap ___ did i miss something? Antoin

Re: [DNSOP] automatic update of DS records

2010-03-03 Thread Mark Andrews
In message dd056a31a84cfc4ab501bd56d1e14bbb73e...@exchange.secure64.com, Stephan Lagerholm writes: From: Jay Daley [mailto:j...@nzrs.net.nz] Sent: Wednesday, March 03, 2010 1:54 PM To: Stephan Lagerholm Cc: Alex Bligh; Jaap Akkerhuis; matth...@nlnetlabs.nl;

Re: [DNSOP] automatic update of DS records

2010-03-03 Thread Alfred Hönes
To avoid further confusion on who said ... snip snip snip ... The last message was from Jaap Akkerhuis, who said: Oops, apparently Alfred said so. But who sais what is irrelevat on the discussion. The oint I was making is that there should not be a fixed aministrative model. jaap