[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: [dnsext] one algorithm number or two
On Thu, Dec 11, 2008 at 02:40:17PM -0500, Edward Lewis wrote:
> But my preference is not to tie RSA/SHA-1 to NSEC3. It's known that I
> have been skeptical of NSEC3, to the irritation of a few people. There's
> no need to go into that again, not now and not here. Whether my
> skepticism is warranted or not, I feel that NSEC3 is still too immature
> to assume that it is an essential core element of DNS or DNSSEC.
Does the above constitute an objection to the direction we've lately
apparently been headed, which was to revert to one identifier? That
is, you seem to be arguing against one identifier, and in favour of
two. How strongly do you feel about it?
A
--
Andrew Sullivan
ajs@shinkuro.com
Shinkuro, Inc.
--
to unsubscribe send a message to namedroppers-request@ops.ietf.org with
the word 'unsubscribe' in a single line as the message text body.
archive: <http://ops.ietf.org/lists/namedroppers/>