Re: [dns-operations] Sharing a DNSSEC key between zones

2015-01-12 Thread Olafur Gudmundsson
> On Jan 9, 2015, at 7:50 AM, Stephane Bortzmeyer wrote: > > I'm looking for resources discussing the pros and cons of sharing > DNSSEC keys between zones. > > I find nothing in RFC 6841 or 6781. Any pointer? > Stephane, I do not think there has been much thought given to this topic, for al

Re: [dns-operations] Sharing a DNSSEC key between zones

2015-01-12 Thread Stephane Bortzmeyer
On Sat, Jan 10, 2015 at 07:46:55PM -0500, Warren Kumari wrote a message of 120 lines which said: > Obligatory marketing message on automating this: > https://tools.ietf.org/html/rfc7344 I would be interested by a Web page / Wiki recording the registries (or, for those who have to use the regi

Re: [dns-operations] Sharing a DNSSEC key between zones

2015-01-10 Thread Warren Kumari
On Friday, January 9, 2015, Tony Finch wrote: > > > On 9 Jan 2015, at 12:50, Stephane Bortzmeyer > wrote: > > > > I'm looking for resources discussing the pros and cons of sharing > > DNSSEC keys between zones. > > > > I find nothing in RFC 6841 or 6781. Any pointer? > > There is a paragraph abo

Re: [dns-operations] Sharing a DNSSEC key between zones

2015-01-10 Thread Peter Koch
On Fri, Jan 09, 2015 at 07:10:28PM +, Tony Finch wrote: > There is a paragraph about this at > http://users.isc.org/~jreed/dnssec-guide/dnssec-guide.html#same-key-for-multiple-zones the argument regarding the extent of a compromise only holds if you think of cryptanalitic rather than operati

Re: [dns-operations] Sharing a DNSSEC key between zones

2015-01-09 Thread Tony Finch
> On 9 Jan 2015, at 12:50, Stephane Bortzmeyer wrote: > > I'm looking for resources discussing the pros and cons of sharing > DNSSEC keys between zones. > > I find nothing in RFC 6841 or 6781. Any pointer? There is a paragraph about this at http://users.isc.org/~jreed/dnssec-guide/dnssec-guid

Re: [dns-operations] Sharing a DNSSEC key between zones

2015-01-09 Thread Jan-Piet Mens
> I'm looking for resources discussing the pros and cons of sharing > DNSSEC keys between zones. Surfnet published a paper in 2012 which discusses a few drawbacks; I don't recall the exact details, but maybe there's something useful there for you. -JP [1] https://dnssec.surfnet.nl/wp-co

[dns-operations] Sharing a DNSSEC key between zones

2015-01-09 Thread Stephane Bortzmeyer
I'm looking for resources discussing the pros and cons of sharing DNSSEC keys between zones. I find nothing in RFC 6841 or 6781. Any pointer? ___ dns-operations mailing list dns-operations@lists.dns-oarc.net https://lists.dns-oarc.net/mailman/listinfo/dn