Re: [Freeipa-devel] DNSSEC support design considerations: key material handling

2013-09-02 Thread Petr Spacek
On 12.8.2013 14:30, Loris Santamaria wrote: El vie, 09-08-2013 a las 16:22 +0200, Petr Spacek escribió: On 9.8.2013 15:12, Rob Crittenden wrote: Simo Sorce wrote: On Fri, 2013-08-09 at 10:42 +0200, Petr Spacek wrote: On 23.7.2013 10:55, Petr Spacek wrote: On 19.7.2013 19:55, Simo Sorce

Re: [Freeipa-devel] DNSSEC support design considerations: key material handling

2013-09-02 Thread Petr Spacek
On 9.8.2013 16:22, Petr Spacek wrote: On 9.8.2013 15:12, Rob Crittenden wrote: Simo Sorce wrote: On Fri, 2013-08-09 at 10:42 +0200, Petr Spacek wrote: On 23.7.2013 10:55, Petr Spacek wrote: On 19.7.2013 19:55, Simo Sorce wrote: I will reply to the rest of the message later if necessary,

Re: [Freeipa-devel] DNSSEC support design considerations: key material handling

2013-08-12 Thread Martin Kosek
On 08/09/2013 04:13 PM, Anthony Messina wrote: On Friday, August 09, 2013 08:49:29 AM Simo Sorce wrote: Dmitri, Martin and me discussed this proposal in person and the new plan is: - Elect one super-master which will handle key generation (as we do with special CA certificates) I guess we

Re: [Freeipa-devel] DNSSEC support design considerations: key material handling

2013-08-12 Thread Loris Santamaria
El vie, 09-08-2013 a las 16:22 +0200, Petr Spacek escribió: On 9.8.2013 15:12, Rob Crittenden wrote: Simo Sorce wrote: On Fri, 2013-08-09 at 10:42 +0200, Petr Spacek wrote: On 23.7.2013 10:55, Petr Spacek wrote: On 19.7.2013 19:55, Simo Sorce wrote: I will reply to the rest of the

Re: [Freeipa-devel] DNSSEC support design considerations: key material handling

2013-08-12 Thread Anthony Messina
On Monday, August 12, 2013 09:34:19 AM Martin Kosek wrote: On 08/09/2013 04:13 PM, Anthony Messina wrote: On Friday, August 09, 2013 08:49:29 AM Simo Sorce wrote: Dmitri, Martin and me discussed this proposal in person and the new plan is: - Elect one super-master which will handle key

Re: [Freeipa-devel] DNSSEC support design considerations: key material handling

2013-08-09 Thread Petr Spacek
On 23.7.2013 10:55, Petr Spacek wrote: On 19.7.2013 19:55, Simo Sorce wrote: I will reply to the rest of the message later if necessary, still digesting some of your answers, but I wanted to address the following first. On Fri, 2013-07-19 at 18:29 +0200, Petr Spacek wrote: The most important

Re: [Freeipa-devel] DNSSEC support design considerations: key material handling

2013-08-09 Thread Simo Sorce
On Fri, 2013-08-09 at 10:42 +0200, Petr Spacek wrote: On 23.7.2013 10:55, Petr Spacek wrote: On 19.7.2013 19:55, Simo Sorce wrote: I will reply to the rest of the message later if necessary, still digesting some of your answers, but I wanted to address the following first. On Fri,

Re: [Freeipa-devel] DNSSEC support design considerations: key material handling

2013-08-09 Thread Rob Crittenden
Simo Sorce wrote: On Fri, 2013-08-09 at 10:42 +0200, Petr Spacek wrote: On 23.7.2013 10:55, Petr Spacek wrote: On 19.7.2013 19:55, Simo Sorce wrote: I will reply to the rest of the message later if necessary, still digesting some of your answers, but I wanted to address the following first.

Re: [Freeipa-devel] DNSSEC support design considerations: key material handling

2013-08-09 Thread Anthony Messina
On Friday, August 09, 2013 08:49:29 AM Simo Sorce wrote: Dmitri, Martin and me discussed this proposal in person and the new plan is: - Elect one super-master which will handle key generation (as we do with special CA certificates) I guess we can start this way, but how do you determine

Re: [Freeipa-devel] DNSSEC support design considerations: key material handling

2013-08-09 Thread Petr Spacek
On 9.8.2013 15:12, Rob Crittenden wrote: Simo Sorce wrote: On Fri, 2013-08-09 at 10:42 +0200, Petr Spacek wrote: On 23.7.2013 10:55, Petr Spacek wrote: On 19.7.2013 19:55, Simo Sorce wrote: I will reply to the rest of the message later if necessary, still digesting some of your answers, but

Re: [Freeipa-devel] DNSSEC support design considerations: key material handling

2013-07-23 Thread Petr Spacek
On 19.7.2013 19:55, Simo Sorce wrote: I will reply to the rest of the message later if necessary, still digesting some of your answers, but I wanted to address the following first. On Fri, 2013-07-19 at 18:29 +0200, Petr Spacek wrote: The most important question at the moment is What can we

Re: [Freeipa-devel] DNSSEC support design considerations: key material handling

2013-07-19 Thread Simo Sorce
I will reply to the rest of the message later if necessary, still digesting some of your answers, but I wanted to address the following first. On Fri, 2013-07-19 at 18:29 +0200, Petr Spacek wrote: The most important question at the moment is What can we postpone? How fragile it can be for

Re: [Freeipa-devel] DNSSEC support design considerations: key material handling

2013-07-17 Thread Simo Sorce
On Tue, 2013-07-16 at 17:15 +0200, Petr Spacek wrote: On 15.7.2013 21:07, Simo Sorce wrote: Is there any place I can read about the format and requirements of these files ? There is no single format, because it is algorithm-dependent. See below. AFAIK it is nothing supported by OpenSSL,

Re: [Freeipa-devel] DNSSEC support design considerations: key material handling

2013-07-16 Thread Petr Spacek
On 15.7.2013 21:07, Simo Sorce wrote: On Mon, 2013-07-15 at 16:58 +0200, Petr Spacek wrote: The remaining part is mostly about key management. Following text mentions 'DNSSEC keys' many times, so I tried to summarize how keys are used in DNSSEC. Feel free to skip it. == DNSSEC theory == Each

Re: [Freeipa-devel] DNSSEC support design considerations: key material handling

2013-07-15 Thread Petr Spacek
Hello, first pair of this message quickly concludes discussion about database part of the DNSSEC support and then key material handling is discussed. I'm sorry for the wall of text. On 27.6.2013 18:43, Simo Sorce wrote: * How to get sorted list of entries from LDAP? Use