[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [dnsext] RRTYPE request: template for proposed RKEY RRtype



On Dec 4 2008, Jim Reid wrote:

On Dec 3, 2008, at 07:08, Samuel Weiler wrote:

[... other points snipped ...]

Without more documentation, it's hard to see how choosing this format enables rollover.

It's just a key. Rollover is irrelevant. When a new key is needed, the old one is retired and the data gets encrypted with the new one. If this isn't done, the decryption fails. Which is the sole responsibility of whoever publishes that key and the encrypted NAPTRs associated with that key.

Unless you are proposing that RKEY records always have a TTL of zero,
you have to deal with the fact that some clients will have old versions of them in their caches. Some sort of overlap mechanism is needed.

--
Chris Thompson
Email: cet1@cam.ac.uk


--
to unsubscribe send a message to namedroppers-request@ops.ietf.org with
the word 'unsubscribe' in a single line as the message text body.
archive: <http://ops.ietf.org/lists/namedroppers/>