Re: [dnsext] Historical root keys: The Large Router Vendor Speaks

Paul Wouters <paul@xelerance.com> Fri, 28 January 2011 20:27 UTC

Return-Path: <paul@xelerance.com>
X-Original-To: dnsext@core3.amsl.com
Delivered-To: dnsext@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id 4289F3A6975 for <dnsext@core3.amsl.com>; Fri, 28 Jan 2011 12:27:28 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.575
X-Spam-Level:
X-Spam-Status: No, score=-2.575 tagged_above=-999 required=5 tests=[AWL=0.024, BAYES_00=-2.599]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 6Bx-wlmdmbIW for <dnsext@core3.amsl.com>; Fri, 28 Jan 2011 12:27:27 -0800 (PST)
Received: from newtla.xelerance.com (newtla.xelerance.com [193.110.157.143]) by core3.amsl.com (Postfix) with ESMTP id 74F483A6968 for <dnsext@ietf.org>; Fri, 28 Jan 2011 12:27:27 -0800 (PST)
Received: from tla.xelerance.com (tla.xelerance.com [193.110.157.130]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by newtla.xelerance.com (Postfix) with ESMTP id B20C0BF8B; Fri, 28 Jan 2011 15:30:32 -0500 (EST)
Date: Fri, 28 Jan 2011 15:30:32 -0500
From: Paul Wouters <paul@xelerance.com>
To: John Bashinski <jbash@cisco.com>
In-Reply-To: <4D431F94.4020701@cisco.com>
Message-ID: <alpine.LFD.1.10.1101281523330.29398@newtla.xelerance.com>
References: <4D41D3E2.6060107@cisco.com> <3125F45F-7594-498F-AFA3-D2D738A228F5@hopcount.ca> <4D42F597.8090006@vpnc.org> <4D42FCB6.70005@cisco.com> <4D43072D.6090503@vpnc.org> <4D431F94.4020701@cisco.com>
User-Agent: Alpine 1.10 (LFD 962 2008-03-14)
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset="US-ASCII"; format="flowed"
Cc: Paul Hoffman <paul.hoffman@vpnc.org>, dnsext@ietf.org
Subject: Re: [dnsext] Historical root keys: The Large Router Vendor Speaks
X-BeenThere: dnsext@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: DNS Extensions working group discussion list <dnsext.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/dnsext>, <mailto:dnsext-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/dnsext>
List-Post: <mailto:dnsext@ietf.org>
List-Help: <mailto:dnsext-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dnsext>, <mailto:dnsext-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 28 Jan 2011 20:27:28 -0000

On Fri, 28 Jan 2011, John Bashinski wrote:

> 2. User able to override the root keys for any subzone:
>
>   a. With a local anchor, or
>   b. With DLV

Note that this can be complicated. If you have a private.example.com
used internally only, then you have to "override" the DNSSEC signed data
that would "proof" that private.example.com does not exist at the parent
(used in the public view).

unbound has supported this for a long time, and bind started suporting
this only in 9.8.x. Be sure your validating stack can deal with this case.

Paul