[dnsext] [Editorial Errata Reported] RFC6840 (4191)

RFC Errata System <rfc-editor@rfc-editor.org> Tue, 02 December 2014 16:37 UTC

Return-Path: <wwwrun@rfc-editor.org>
X-Original-To: dnsext@ietfa.amsl.com
Delivered-To: dnsext@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 8E6CA1A1C04 for <dnsext@ietfa.amsl.com>; Tue, 2 Dec 2014 08:37:16 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -6.912
X-Spam-Level:
X-Spam-Status: No, score=-6.912 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_HI=-5, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id YQZMtXIbYCyy for <dnsext@ietfa.amsl.com>; Tue, 2 Dec 2014 08:37:15 -0800 (PST)
Received: from rfc-editor.org (rfc-editor.org [4.31.198.49]) by ietfa.amsl.com (Postfix) with ESMTP id 295D61A1BF3 for <dnsext@ietf.org>; Tue, 2 Dec 2014 08:37:15 -0800 (PST)
Received: by rfc-editor.org (Postfix, from userid 30) id E4BFC18123F; Tue, 2 Dec 2014 08:36:46 -0800 (PST)
To: weiler@tislabs.com, davidb@verisign.com, brian@innovationslab.net, ted.lemon@nominum.com, ogud@ogud.com, ajs@anvilwalrusden.com
X-PHP-Originating-Script: 6000:errata_mail_lib.php
From: RFC Errata System <rfc-editor@rfc-editor.org>
Message-Id: <20141202163646.E4BFC18123F@rfc-editor.org>
Date: Tue, 02 Dec 2014 08:36:46 -0800
Archived-At: http://mailarchive.ietf.org/arch/msg/dnsext/4KM5gHO84ndayHWbvVZpOcBr9JU
Cc: edward.lewis@icann.org, dnsext@ietf.org, rfc-editor@rfc-editor.org
Subject: [dnsext] [Editorial Errata Reported] RFC6840 (4191)
X-BeenThere: dnsext@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: DNS Extensions working group discussion list <dnsext.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dnsext>, <mailto:dnsext-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/dnsext/>
List-Post: <mailto:dnsext@ietf.org>
List-Help: <mailto:dnsext-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dnsext>, <mailto:dnsext-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 02 Dec 2014 16:37:16 -0000

The following errata report has been submitted for RFC6840,
"Clarifications and Implementation Notes for DNS Security (DNSSEC)".

--------------------------------------
You may review the report below and at:
http://www.rfc-editor.org/errata_search.php?rfc=6840&eid=4191

--------------------------------------
Type: Editorial
Reported by: Edward Lewis <edward.lewis@icann.org>

Section: 5.11

Original Text
-------------
...

A signed zone MUST include a DNSKEY for each algorithm present in
      the zone's DS RRset and expected trust anchors for the zone.  The
      zone MUST also be signed with each algorithm (though not each key)
      present in the DNSKEY RRset.  

Corrected Text
--------------
A signed zone MUST include a DNSKEY for each algorithm present in
      the zone's DS RRset and expected trust anchors for the zone.  Each
      authoritative RRset in the zone MUST be signed with each 
      algorithm (though not each key) present in the DNSKEY RRset.  

Notes
-----
Zones aren't signed (per se), the data sets within them are.  But not cut point (NS) and glue.

Instructions:
-------------
This erratum is currently posted as "Reported". If necessary, please
use "Reply All" to discuss whether it should be verified or
rejected. When a decision is reached, the verifying party (IESG)
can log in to change the status and edit the report, if necessary. 

--------------------------------------
RFC6840 (draft-ietf-dnsext-dnssec-bis-updates-20)
--------------------------------------
Title               : Clarifications and Implementation Notes for DNS Security (DNSSEC)
Publication Date    : February 2013
Author(s)           : S. Weiler, Ed., D. Blacka, Ed.
Category            : PROPOSED STANDARD
Source              : DNS Extensions
Area                : Internet
Stream              : IETF
Verifying Party     : IESG