Re: .gov DNSSEC operational message - picking a fight

2010-12-29 Thread bmanning
On Wed, Dec 29, 2010 at 02:56:35PM +, Tony Finch wrote: On 28 Dec 2010, at 22:46, bmann...@vacation.karoshi.com wrote: IMHO, key management should be able to use an OOB channel when the in-band is corrupted or overlaoded. Reliance on strictly the IB channel presumes there

Re: .gov DNSSEC operational message - picking a fight

2010-12-28 Thread bmanning
On Tue, Dec 28, 2010 at 11:41:18AM -0800, Doug Barton wrote: Now OTOH if someone wants to demonstrate the value in having a publication channel for TLD DNSKEYs outside of the root zone, I'm certainly willing to listen. Just be forewarned that you will have an uphill battle in trying to prove

Re: .gov DNSSEC operational message - picking a fight

2010-12-28 Thread Doug Barton
On 12/28/2010 14:46, bmann...@vacation.karoshi.com wrote: On Tue, Dec 28, 2010 at 11:41:18AM -0800, Doug Barton wrote: Now OTOH if someone wants to demonstrate the value in having a publication channel for TLD DNSKEYs outside of the root zone, I'm certainly willing to listen. Just be