[dnssec-key-tf] Using the TAR for non-TLD KSKs
Johan Ihren
Thu Oct 25 11:05:40 CEST 2007
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 On 24 Oct 2007, at 23:48, Jim Reid wrote: > On Oct 24, 2007, at 16:54, Johan Ihren wrote: > >> However, what is more important: providing a relevant service that >> justifies this effort in the first place or having a sufficiently >> simple exit strategy? > > This is not an either/or question. IMO the service cannot be > relevant unless it has a simple and clear exit strategy. Fair enough. So then we need to figure out an exit strategy that is sufficiently clear and still deals with non-TLD keys. How about "TAR will shutdown 12 months after the root is signed"? I'm not saying that's a perfect strategy, but it would address the present of tieing TAR to TLDs when there's no underlying reason for that other than the exit strategy. Johan -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.5 (Darwin) iQCVAwUBRyBcZ/otlDfa2H4ZAQI9cAQAnV5aV1PteviTG8OPKmYblggEhpl2sYDk 4vd2O6ItvYNYOOF1Cu9V8AtqSUJPVo7zNwZhZ1PT8n3RvM7jtSAgYjO92DyBGYBF TruDx4r0wjw01b0QZAGP0+r0aJ+rXyymFftSPp5FkIpl7tS1227iJJ0n9XT9SPbM U7PZbEr+SLA= =3+Ul -----END PGP SIGNATURE-----