This archive is retained to ensure existing URLs remain functional. It will not contain any emails sent to this mailing list after July 1, 2024. For all messages, including those sent before and after this date, please visit the new location of the archive at https://mailman.ripe.net/archives/list/[email protected]/
[dns-wg] Re: New key-signing keys (KSKs) for RIPE NCC forward and reverse zones
- Previous message (by thread): [dns-wg] New key-signing keys (KSKs) for RIPE NCC forward and reverse zones
- Next message (by thread): [dns-wg] Re: New key-signing keys (KSKs) for RIPE NCC forward and reverse zones
Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
Anand Buddhdev
anandb at ripe.net
Tue Mar 17 12:26:57 CET 2009
Lutz Donnerhacke wrote: >> On 12 March 2009, the RIPE NCC generated new key-signing keys (KSKs) for >> all the DNSSEC-signed zones that it operates. We have published updated >> trust anchor files for inclusion in validating resolvers. > > Are you going to use RFC 5011 to remove the old keys? Hello Lutz, The toolset that we're using does not have support for setting the revocation bit, so we won't be setting it. Are many people actually running resolvers that understand RFC 5011? -- Anand Buddhdev DNS Services Manager, RIPE NCC
- Previous message (by thread): [dns-wg] New key-signing keys (KSKs) for RIPE NCC forward and reverse zones
- Next message (by thread): [dns-wg] Re: New key-signing keys (KSKs) for RIPE NCC forward and reverse zones
Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
[ dns-wg Archives ]