[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: [dnsext] RRTYPE request: template for proposed RKEY RRtype
On Dec 4 2008, Jim Reid wrote:
On Dec 3, 2008, at 07:08, Samuel Weiler wrote:
[... other points snipped ...]
Without more documentation, it's hard to see how choosing this
format enables rollover.
It's just a key. Rollover is irrelevant. When a new key is needed, the
old one is retired and the data gets encrypted with the new one. If
this isn't done, the decryption fails. Which is the sole
responsibility of whoever publishes that key and the encrypted NAPTRs
associated with that key.
Unless you are proposing that RKEY records always have a TTL of zero,
you have to deal with the fact that some clients will have old versions
of them in their caches. Some sort of overlap mechanism is needed.
--
Chris Thompson
Email: cet1@cam.ac.uk
--
to unsubscribe send a message to namedroppers-request@ops.ietf.org with
the word 'unsubscribe' in a single line as the message text body.
archive: <http://ops.ietf.org/lists/namedroppers/>