From brettcarr at ripe.net Thu Jan 4 15:33:13 2007 From: brettcarr at ripe.net (Brett Carr) Date: Thu, 4 Jan 2007 15:33:13 +0100 (CET) Subject: [dns-wg] [dnssec-deployment] New KSK for .SE (fwd) Message-ID: I think that this may interest some folks on this list. -- Brett Carr RIPE Network Coordination Centre Manager -- DNS Services Group Singel 258 Amsterdam NL GPG Key fingerprint = F20D B2A7 C91D E370 44CF F244 B6A1 EF48 E743 F7D8 ---------- Forwarded message ---------- Date: Thu, 4 Jan 2007 12:26:25 +0100 From: "[iso-8859-1] Anne-Marie Eklund-L?winder" To: DNSSEC deployment Subject: [dnssec-deployment] New KSK for .SE -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 New key signing key (KSK) for .SE As from today, 2007-01-04 .SE publish and take into use a new KSK for signing the .SE zone file. The old key will be valid until 2008-01-01. If you have configured the old key (Key id = 17686) into your resolver we strongly recommend you to replace it with the new key (Key id = 6166) no later than 2007-12-31. Following public keys are valid for .SE: se. IN DNSKEY 257 3 5 ( AwEAAaxPMcR2x0HbQV4WeZB6oEDX+r0QM65KbhTjrW1Z aARmPhEZZe3Y9ifgEuq7vZ/zGZUdEGNWy+JZzus0lUpt wgjGwhUS1558Hb4JKUbbOTcM8pwXlj0EiX3oDFVmjHO4 44gLkBOUKUf/mC7HvfwYH/Be22GnClrinKJp1Og4ywzO 9WglMk7jbfW33gUKvirTHr25GL7STQUzBb5Usxt8lgny TUHs1t3JwCY5hKZ6CqFxmAVZP20igTixin/1LcrgX/KM EGd/buvF4qJCyduieHukuY3H4XMAcR+xia2nIUPvm/oy WR8BW/hWdzOvnSCThlHf3xiYleDbt/o1OTQ09A0= ) ; key id = 17686 se. IN DNSKEY 257 3 5 ( AwEAAb6xRZHEf+PyF5dxEvz0BHEHbziu6iZaiNW/yjSa ZcmrmZiRMF8FPppD+XuKSau0rgu4eBwYdpkEoMVR4FhI 8frkuPHIue2LP1ETo+2hCrdr60K1538yLvzbOhMxXt6k njPN+OlalMmCknadaofKga5FLKOPQs2C3nw6AH4WUNGr chmDMVBwRwfZdQXYZTXesqULmGMK7mwjQGOxerRDQWrF v8NhNnVV31PihaYBdQ1TJjvfGS/FYZJwv/BddiELiLeU nNWu3AOsRAshgOcDBOAPUvKJNEq6RHELFmvXOOe2d8H2 yzv02EMQik6GwUm16DrSdmX+SWfelQs+9ELFN6k= ) ; key id = 6166 The keys are also available at http://dnssec.iis.se/key.html DNS users that haven't earlier but are going to configure their DNS to ask for DNSSEC answers should only use the new key. DNS users that haven't explicitly configured their DNS to ask for DNSSEC answers this will not involve any changes at all. We do also advice you to subscribe to the dnssec-announce at lists.nic.se mailing list to get notified about key rollovers and any other important changes Questions may be addressed to dnssec-info at iis.se Anne-Marie Eklund L?winder Quality & Security Manager .SE (The Internet Infrastructure Foundation) P O Box 7399 103 91 Stockholm Sweden Tel: +46 8 452 35 00, direct: +46 8 452 35 17, mobile: +46 734 315 310 E-mail: anne-marie.eklund-lowinder at iis.se Web: www.iis.se -----BEGIN PGP SIGNATURE----- Version: PGP 8.1 iQA/AwUBRZzkYaXc8AFCsc+UEQLWwwCaAibkesPscNtzsjeWWLmrFKLcaa8AoJli +i6VDyKfg8wqbW9lkCwynJY5 =YaRn -----END PGP SIGNATURE----- ############################################################# This message is sent to you because you are subscribed to the mailing list . To unsubscribe, E-mail to: A public archive is available here: and older material is at From Anne-Marie.Eklund-Lowinder at iis.se Fri Jan 5 11:40:06 2007 From: Anne-Marie.Eklund-Lowinder at iis.se (=?iso-8859-1?Q?Anne-Marie_Eklund-L=F6winder?=) Date: Fri, 5 Jan 2007 11:40:06 +0100 Subject: [dns-wg] New KSK for .SE Message-ID: <023E9DDFC555E3479AEBF917CE60A0B4A903E5@EXCHANGE.office.nic.se> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 New key signing key (KSK) for .SE As from 2007-01-04 .SE publish and take into use a new KSK for signing the .SE zone file. The old key will be valid until 2008-01-01. If you have configured the old key (Key id = 17686) into your resolver we strongly recommend you to replace it with the new key (Key id = 6166) no later than 2007-12-31. Following public keys are valid for .SE: se. IN DNSKEY 257 3 5 ( AwEAAaxPMcR2x0HbQV4WeZB6oEDX+r0QM65KbhTjrW1Z aARmPhEZZe3Y9ifgEuq7vZ/zGZUdEGNWy+JZzus0lUpt wgjGwhUS1558Hb4JKUbbOTcM8pwXlj0EiX3oDFVmjHO4 44gLkBOUKUf/mC7HvfwYH/Be22GnClrinKJp1Og4ywzO 9WglMk7jbfW33gUKvirTHr25GL7STQUzBb5Usxt8lgny TUHs1t3JwCY5hKZ6CqFxmAVZP20igTixin/1LcrgX/KM EGd/buvF4qJCyduieHukuY3H4XMAcR+xia2nIUPvm/oy WR8BW/hWdzOvnSCThlHf3xiYleDbt/o1OTQ09A0= ) ; key id = 17686 se. IN DNSKEY 257 3 5 ( AwEAAb6xRZHEf+PyF5dxEvz0BHEHbziu6iZaiNW/yjSa ZcmrmZiRMF8FPppD+XuKSau0rgu4eBwYdpkEoMVR4FhI 8frkuPHIue2LP1ETo+2hCrdr60K1538yLvzbOhMxXt6k njPN+OlalMmCknadaofKga5FLKOPQs2C3nw6AH4WUNGr chmDMVBwRwfZdQXYZTXesqULmGMK7mwjQGOxerRDQWrF v8NhNnVV31PihaYBdQ1TJjvfGS/FYZJwv/BddiELiLeU nNWu3AOsRAshgOcDBOAPUvKJNEq6RHELFmvXOOe2d8H2 yzv02EMQik6GwUm16DrSdmX+SWfelQs+9ELFN6k= ) ; key id = 6166 The keys are also available at http://dnssec.iis.se/key.html DNS users that haven't earlier but are going to configure their DNS to ask for DNSSEC answers should only use the new key. DNS users that haven't explicitly configured their DNS to ask for DNSSEC answers this will not involve any changes at all. We do also advice you to subscribe to the dnssec-announce at lists.nic.se mailing list to get notified about key rollovers and any other important changes. Questions may be addressed to dnssec-info at iis.se. Anne-Marie Eklund L?winder Quality & Security Manager .SE (The Internet Infrastructure Foundation) P O Box 7399 103 91 Stockholm Sweden Tel: +46 8 452 35 00, direct: +46 8 452 35 17, mobile: +46 734 315 310 E-mail: anne-marie.eklund-lowinder at iis.se Web: www.iis.se -----BEGIN PGP SIGNATURE----- Version: PGP 8.1 iQA/AwUBRZ4rBqXc8AFCsc+UEQKMfgCeIFq1xZiK0XJLa5QEyiPZ1qtW1coAnAvy q0tq5ATA3Ldlfa0DoChKUEGJ =LgnA -----END PGP SIGNATURE----- From jim at rfc1035.com Tue Jan 23 13:56:58 2007 From: jim at rfc1035.com (Jim Reid) Date: Tue, 23 Jan 2007 12:56:58 +0000 Subject: [dns-wg] Lameness Checking Draft Message-ID: Colleagues, the lame delegation draft -- http://www.ripe.net/ripe/ draft-documents/dns-lameness.html -- that was produced by the WG has completed an uneventful Last Call. So this means we have consensus and the draft now goes forward as a RIPE document. The WG co-chairs thank everyone who contributed to this document. Special thanks are due to Brett Carr who did most of the heavy lifting to produce the document. From jim at rfc1035.com Tue Jan 23 14:02:51 2007 From: jim at rfc1035.com (Jim Reid) Date: Tue, 23 Jan 2007 13:02:51 +0000 Subject: [dns-wg] Lameness Checking Draft Message-ID: Colleagues, the lame delegation draft -- http://www.ripe.net/ripe/ draft-documents/dns-lameness.html -- that was produced by the WG has completed an uneventful Last Call. So this means we have consensus and the draft now goes forward as a RIPE document. [Silence implies consent.:-)] The WG co-chairs thank everyone who contributed to this document. Special thanks are due to Brett Carr who did most of the heavy lifting to produce the document. The NCC is now starting on implementation. Brett's team are documenting the software requirements and hope to have a limited demo available for RIPE54. From jim at rfc1035.com Wed Jan 24 19:55:36 2007 From: jim at rfc1035.com (Jim Reid) Date: Wed, 24 Jan 2007 18:55:36 +0000 Subject: [dns-wg] Our RIPE document has been published Message-ID: <8F5162BB-65E4-4EFC-B843-E93B45B73AED@rfc1035.com> Here's the news from the NCC's webmaster: Your draft-document has been published at http://www.ripe.net/ripe/docs/ripe-400.html I have also made changes to all of the associated pages. http://www.ripe.net/ripe/draft-documents/index.html - removal of your draft doc. http://www.ripe.net/ripe/docs/index.html - inclusion of ripe-400 under the heading 'recently published' and 'information services documents'. http://www.ripe.net/ripe/docs/titletoc.html If you require further amendments please let me know. Kind regards, Nichola From ncc at ripe.net Mon Jan 29 17:07:57 2007 From: ncc at ripe.net (RIPE NCC) Date: Mon, 29 Jan 2007 17:07:57 +0100 (CET) Subject: [dns-wg] RIPE NCC Planned Maintenance, February 2007 Message-ID: 1170087040.05310 [Apologies for duplicate e-mails] Dear Colleagues, The RIPE NCC will perform planned maintenance work that will affect a number of servers. The maintenance work will take place on: Thursday, 1 February 2007 between 21:00 and 23:00 UTC Wednesday, 7 February 2007 between 21:00 and 23:00 UTC During this maintenance, individual servers may experience short outages. We apologise for any inconvenience that this may cause. If you have any questions about this, please send an e-mail to: ops at ripe.net