Skip to main content

Draft of Introducing DNSSEC Service to Reverse DNS Trees

This policy proposal has been accepted

It is possible to secure delegations from the RIPE NCC under the Policy for Reverse Address Delegation of IPv4 and IPv6 Address Space in the RIPE NCC Service Region.

Our operational staff will deploy DNSSEC zone by zone. We will only exchange keys when parent domains are being signed. This will keep information current.

Key exchange between parent and child is based on the same authorisation and authentication mechanisms as the exchange of nameserver delegation information.

We will sign any announcements about secured DNS, such as changes in RIPE NCC procedures, with our PGP key. We will publish procedures and announcements on our secure website and also post these to an announcement mailing list.