Re: [dns-wg] NTIA and RIPE v3
-
To: Richard Lamb <richard.lamb@localhost
-
From: Patrik Fältström paf@localhost
-
Date: Thu, 30 Oct 2008 07:30:15 +0400
-
Authentication-results: ams-dkim-2; header.From=paf@localhost dkim=pass ( sig from cisco.com/amsdkim2001 verified; );
-
Cc: "dns-wg@localhost" dns-wg@localhost
-
Dkim-signature: v=1; a=rsa-sha256; q=dns/txt; l=470; t=1225337415; x=1226201415; c=relaxed/simple; s=amsdkim2001; h=Content-Type:From:Subject:Content-Transfer-Encoding:MIME-Version; d=cisco.com; i=paf@localhost z=From:=20=3D?ISO-8859-1?Q?Patrik_F=3DE4ltstr=3DF6m?=3D=20<p af@localhost |Subject:=20Re=3A=20[dns-wg]=20NTIA=20and=20RIPE=20v3 |Sender:=20; bh=CgXmjF8vrQW25OAvZttm6B1YkJ83R7CLkuu/HrdFpR0=; b=Vo+TK/o10lPHKPNMSghnTUxwQC3z+APOJ9JkfCSCngTJ3yDO+UqlZqhPtJ nsJp6vNYqfp7Qn2sS7/bD9Cux/qUS/ty908Wt9mJt/old+Kd5tlsmzIKsyS6 cQPe337Tm3;
On 29 okt 2008, at 22.50, Richard Lamb wrote:
Great points but they miss the fundamental importance of providing a
secure solution from TLD operator to signed root. So I would
recommend the bullet:
L - The solution has to balance various concerns, but must provide
for a maximally secure technical solution and one that provides the
trust promised by DNSSEC.
Thanks, added to the list that we will look at this morning.
Patrik
|