[dns-wg] RIPE NCC DNSSEC on the reverse tree update.
-
From: "Brett Carr" <>
-
Date: Thu, 24 Nov 2005 14:13:29 +0100
Dear Colleagues,
As part of the project to deploy DNSSEC in the RIPE NCC service region, the
RIPE NCC has further expanded the signing of zones from the reverse tree.
The following zones are now signed:
ripe.net
ripencc.com
ripencc.net
ripencc.org
ripe-ncc.com
ripe-ncc.net
ripe-ncc.org
89.in-addr.arpa
90.in-addr.arpa
213.in-addr.arpa
213.in-addr.arpa.
193.in-addr.arpa.
195.in-addr.arpa.
212.in-addr.arpa.
194.in-addr.arpa.
145.in-addr.arpa.
If you want to configure your resolvers to verify these zones using DNSSEC,
*key signing keys* for these zones are available at:
https://www.ripe.net/projects/disi/keys/ripe-ncc-dnssec-keys.txt
For information about how to use the keys, and for further details about
DNSSEC deployment at the RIPE NCC, please see:
http://www.ripe.net/projects/disi/keys/
The following zones will now accept secure delegations (DS Records) via the
addition of a "ds-rdata:" record in the whois domain object for the zone:
89.in-addr.arpa.
90.in-addr.arpa.
213.in-addr.arpa.
193.in-addr.arpa.
195.in-addr.arpa.
Regards
Brett Carr
RIPE NCC
|