Re: [DNSOP] WGLC: DNSSEC Trust Anchor Configuration and Maintenance

2009-05-12 Thread Edward Lewis
At 14:08 -0400 5/12/09, Olafur Gudmundsson wrote: We are trying to say that the key can be both KSK and ZSK but does not have to be. Oh... How about: "this DNSKEY might also be a zone signing key"? Yeah. Well RFC5011 requires you scan at least once a month, and recommends higher frequency

Re: [DNSOP] WGLC: DNSSEC Trust Anchor Configuration and Maintenance

2009-05-12 Thread bmanning
On Tue, May 12, 2009 at 04:28:01PM -0400, Paul Wouters wrote: > On Tue, 12 May 2009, Olafur Gudmundsson wrote: > > >>Section 3: "Priming can occur when the validating resolver starts, but a > >>validating resolver SHOULD defer priming of individual trust anchors > >>until each is first needed fo

Re: [DNSOP] WGLC: DNSSEC Trust Anchor Configuration and Maintenance

2009-05-12 Thread Paul Wouters
On Tue, 12 May 2009, Olafur Gudmundsson wrote: Section 3: "Priming can occur when the validating resolver starts, but a validating resolver SHOULD defer priming of individual trust anchors until each is first needed for verification." I disagree with this as a SHOULD; "may want to" is much mor

Re: [DNSOP] WGLC: DNSSEC Trust Anchor Configuration and Maintenance

2009-05-12 Thread Olafur Gudmundsson
At 15:05 22/04/2009, Paul Wouters wrote: On Wed, 22 Apr 2009, Peter Koch wrote: Please review the draft and send comments and/or statements of support or non-support to the WG mailing list. It seems a comma is missing between Scott's name and mine. Fixed, One issue came up recently with

Re: [DNSOP] WGLC: DNSSEC Trust Anchor Configuration and Maintenance

2009-05-12 Thread Olafur Gudmundsson
At 14:45 22/04/2009, Edward Lewis wrote: At 20:13 +0200 4/22/09, Peter Koch wrote: >this is to initiate a working group last call on > >"DNSSEC Trust Anchor Configuration and Maintenance" > draft-ietf-dnsop-dnssec-trust-anchor-03.txt > >ending Friday, 2009-05-08, 23:59 UTC. The too

Re: [DNSOP] WGLC: DNSSEC Trust Anchor Configuration and Maintenance

2009-05-12 Thread Paul Hoffman
At 1:48 PM -0400 5/12/09, Olafur Gudmundsson wrote: >At 22:30 29/04/2009, Paul Hoffman wrote: >>At 8:13 PM +0200 4/22/09, Peter Koch wrote: >>>Please review the draft and send comments and/or statements of support or >>>non-support to the WG mailing list. >>>There will be a five reviewer threshold.

Re: [DNSOP] WGLC: DNSSEC Trust Anchor Configuration and Maintenance

2009-05-12 Thread Olafur Gudmundsson
At 22:30 29/04/2009, Paul Hoffman wrote: At 8:13 PM +0200 4/22/09, Peter Koch wrote: >Please review the draft and send comments and/or statements of support or >non-support to the WG mailing list. >There will be a five reviewer threshold. I support the publication of this document. Some comments