On Thu, 17 Nov 2016, Ondřej Surý wrote:
Mikael,the operation of the root zone and signing of the root zone is in the ICANN/IANA bailiwick. Therefore most of the relevant document to the RZ DNSSEC operations can be found at https://www.iana.org/dnssec/ and the document you are most interested in is here: http://data.iana.org/root-anchors/draft-icann-dnssec-trust-anchor.html + the files https://www.iana.org/dnssec/files It might be worth letting them know if you feel that the documentation is incomplete or inaccurate.
That document lists where I can get stuff. It doesn't list any procedures or recommendations how I would get from my non-DNSSEC working state (or even suggestions how I understand that I am in that state and it's because my key material is too old) , perform some operations, and now I understand that I am in a working state.
That's what a BCP could do. -- Mikael Abrahamsson email: swm...@swm.pp.se
_______________________________________________ DNSOP mailing list DNSOP@ietf.org https://www.ietf.org/mailman/listinfo/dnsop