[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: implied NSEC3 support in rsasha256 (was: [dnsext] Re: Working Group Last Call for draft-ietf-dnsext-dnssec-rsasha256-05)




On Dec 10, 2008, at 4:16 PM, Andrew Sullivan wrote:

I think the second option imposes on the whole IETF a burden it
shouldn't have to face: we should have settled this in the WG.


Personally I do not see that as a problem. The IETF has seen heavier burdens caused by cookies. Once the WG has agreed then its up for the AD to judge if this needs another IETF LC. If so, that is process that the IETF has been designed to handle.

My personal preference: Handle this in the WG, make sure we have hammered out all the issues and adapt a text. Then ask the AD for guidance on the next step.


FWIW, I think that we are dealing with a fairly academic issue given that major TLDs move towards NSEC3 and any serious resolver will need to support NSEC3 for DNSSEC and therefore I support Jelte's text.

--Olaf

Attachment: PGP.sig
Description: This is a digitally signed message part