Re: NGtrans - DNSext joint meeting, call for participation

Mark.Andrews@nominum.com Sun, 29 July 2001 05:52 UTC

Received: from psg.com (exim@psg.com [147.28.0.62]) by ietf.org (8.9.1a/8.9.1a) with SMTP id BAA13872 for <dnsext-archive@lists.ietf.org>; Sun, 29 Jul 2001 01:52:19 -0400 (EDT)
Received: from lserv by psg.com with local (Exim 3.31 #1) id 15QX4U-000E6d-00 for namedroppers-data@psg.com; Sat, 28 Jul 2001 09:36:10 -0700
Received: from rip.psg.com ([147.28.0.39] ident=exim) by psg.com with esmtp (Exim 3.31 #1) id 15QX4U-000E6X-00 for namedroppers@ops.ietf.org; Sat, 28 Jul 2001 09:36:10 -0700
Received: from randy by rip.psg.com with local (Exim 3.31 #1) id 15QX4U-000PBg-00 for namedroppers@ops.ietf.org; Sat, 28 Jul 2001 09:36:10 -0700
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
From: Mark.Andrews@nominum.com
To: Mark.Andrews@nominum.com
Cc: "D. J. Bernstein" <djb@cr.yp.to>, ngtrans@sunroof.eng.sun.com, namedroppers@ops.ietf.org, ipng@sunroof.eng.sun.com, dnsop@cafax.se
Subject: Re: NGtrans - DNSext joint meeting, call for participation
In-reply-to: Your message of "Sat, 28 Jul 2001 17:38:08 +1000." <200107280738.f6S7c8u63269@drugs.dv.isc.org>
Sender: owner-namedroppers@ops.ietf.org
Precedence: bulk
Message-Id: <E15QX4U-000E6d-00@psg.com>
Date: Sat, 28 Jul 2001 09:36:10 -0700
Content-Transfer-Encoding: 7bit

	Third time lucky ...

> 	Dan,
> 	     your claim is that you have to re-sign every record in
> 	a zone daily to achieve a 1 day replay window.  I'm stating
> 	that you can achieve the same protection without re-signing
> 	every record daily.
> 
> 	Pre change:
> 	example.com KEY alpha
> 	example.com SIG KEY expire=200107292257 (1 day)
> 	host.example.com A 1.2.3.4
> 	host.example.com SIG A expire=200108272257 (30 days)
> 
> 	Post change:
> 	example.com KEY beta
> 	example.com SIG KEY expire=200107072258 (1 day)

	This should have been
 	example.com SIG KEY expire=200107292258 (1 day)

> 	host.example.com A 1.2.3.5
> 	host.example.com SIG A expire=200108272258 (30 days)
> 
> 	Please explain how you can verify
> 	host.example.com A 1.2.3.4
>         host.example.com SIG A expire=200108272257
> 	after 200107292257.
> 
> 	Mark
--
Mark Andrews, Nominum Inc.
1 Seymour St., Dundas Valley, NSW 2117, Australia
PHONE: +61 2 9871 4742                 INTERNET: Mark.Andrews@nominum.com


to unsubscribe send a message to namedroppers-request@ops.ietf.org with
the word 'unsubscribe' in a single line as the message text body.