Re: [DNSOP] algorithm rollover use cases (was: Signed TLD status)

2010-10-22 Thread Olaf Kolkman
On Sep 30, 2010, at 3:03 PM, Matthijs Mekking wrote a long mail starting with: > > On the dnssec-deployment list, the Signed TLD status thread [1] evolved > into a discussion how algorithm rollover works in specific use cases. My > feeling is that this discussion belongs to DNSOP and so I want to

Re: [DNSOP] algorithm rollover use cases (was: Signed TLD status)

2010-09-30 Thread Matthijs Mekking
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Minor clarification in the final table (thanks Wouter). RRSIG_Z_2 in step 4b and 5 should be RRSIG_K_2. Matthijs On 09/30/2010 03:03 PM, Matthijs Mekking wrote: > c) Both a) and b) >

[DNSOP] algorithm rollover use cases (was: Signed TLD status)

2010-09-30 Thread Matthijs Mekking
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hi, On the dnssec-deployment list, the Signed TLD status thread [1] evolved into a discussion how algorithm rollover works in specific use cases. My feeling is that this discussion belongs to DNSOP and so I want to share my conclusions here. The algo