[dnssec-key-tf] Publication method (was: DLV and trust anchor repositories)
Daniel Karrenberg
Thu Sep 27 18:14:56 CEST 2007
On 27.09 18:01, Peter Koch wrote: > Hi Daniel, > > > ... deafening silence ... are we considering our job done by > > the good folks at the IANA? > > now that you ask -- I, for one, don't. An alternative, err, additional, > root zone with DNSSEC is not really the outcome I'd like to see. > For reasons of clarity and uniqueness I think the TAR should be published > in one standard way, e.g. list of DS RRs or maybe an S/Key or OPIE like > mnemonics based list of DSes. Then, (pointers to) conversion tools will > help making this list usable in various validators. What exactly is the problem with conversion tools that go to ns.iana.org:53 (and a possible list of secondary places), get the zone, validate the sig and then spit out whatever format is necessary for their particular output format? Are we entering the realm of the complications department? Daniel