I have read the most recent version and sent some editorial comments
directly to the authors.

I have finally got around looking at the open-issues tracker and saw the
"Review-NIST" ticket.  In short, I believe that it can be closed out.  The
recommendations in NIST SP 800-81r1 are really an attempt to shoehorn the
general requirements for crypto in the US Federal Gov into DNSSEC.  "Your
Mileage May Vary" fits here as other enterprises/zones have different
security concerns and may not agree with the recommendations.

For example, the suggested parameters in:
http://www.dnssec-deployment.org/documents/SettingtheParameters.pdf  also
differs from the US Federal Gov recommendations but is meant to be a guide
for private organizations.


On 2/26/10 3:06 AM, "Olaf Kolkman" <o...@nlnetlabs.nl> wrote:
> Colleagues,
> I have just posted RFC4641bis version 2.
> The document contains a number of significant changes which address a number
> of the open-issues (see
> http://www.nlnetlabs.nl/svn/rfc4641bis/trunk/open-issues/). In some cases text
> has been rewritten in such a way that it is not immediately obvious if some of
> the open issues are still relevant. Since today was the last opportunity for
> me to submit the document before the cut-off and I believe the text is close
> enough for review on substance and gathering feedback.
> Although a review on (english) style, nits and spelling would be appreciated I
> believe that can wait until the review on substance has taken place.
> http://www.ietf.org/id/draft-ietf-dnsop-rfc4641bis-02.txt
> Once the document is available through the tools interface you should be able
> to study the diffs.
> http://tools.ietf.org/html/draft-ietf-dnsop-rfc4641bis
> --Olaf
> ________________________________________________________
> Olaf M. Kolkman                        NLnet Labs
>                                        Science Park 140,
> http://www.nlnetlabs.nl/               1098 XG Amsterdam
> _______________________________________________
> DNSOP mailing list
> DNSOP@ietf.org
> https://www.ietf.org/mailman/listinfo/dnsop

Scott Rose
ph: +1 301-975-8439
Google Voice: +1-571-249-3671


DNSOP mailing list

Reply via email to