About RIPE | Contact  | Search | Sitemap    
Homepage RIPE  
RIPE Community Mail Archives
search  
     
RIPE Navigation Ends
About RIPE Maillists
Maillists Archive
Global Lists
Non Active Lists
RIPE NCC Navigation Ends
Next Section

Re: [dns-wg] DNSSEC Policy Development Process

  • To: Jim Reid <
    >
  • From: Randy Bush <
    >
  • Date: Mon, 29 Aug 2005 07:06:51 -1000

> Randy, you've confused me. What aspect of DNSSEC specifically "does  
> not scale"? Do you mean having everyone embed trust anchors in their  
> name server configurations for every signed TLD while we wait for the  
> root to be signed?

yep

> If so, I agree that's not scalable. But that's not what was under
> discussion here. At least I hope it wasn't.

no.  you just want me to hold the trust keys for the zones you
think are important.  and, in today's email (for some value of
'today'), brett warns us that he has a handful of third level
zones he thinks are important enough.

hence "does not scale."

randy




 

Next Section
     About RIPE | Site Map | LIR Portal | About the RIPE NCC | Contact | © RIPE Community. All rights reserved.
RIPE.NET Homepage LIR Portal RIPE Community