Re: [dnsext] CDS RRTYPE review - Comments period end Mar 29th

Miek Gieben <miek@miek.nl> Wed, 09 March 2011 07:58 UTC

Return-Path: <miekg@atoom.net>
X-Original-To: dnsext@core3.amsl.com
Delivered-To: dnsext@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id 1681F3A6878 for <dnsext@core3.amsl.com>; Tue, 8 Mar 2011 23:58:58 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.6
X-Spam-Level:
X-Spam-Status: No, score=-2.6 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, NO_RELAYS=-0.001]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id b0rxXmMuwKHB for <dnsext@core3.amsl.com>; Tue, 8 Mar 2011 23:58:54 -0800 (PST)
Received: from elektron.atoom.net (cl-201.ede-01.nl.sixxs.net [IPv6:2001:7b8:2ff:c8::2]) by core3.amsl.com (Postfix) with ESMTP id EF75B3A6850 for <dnsext@ietf.org>; Tue, 8 Mar 2011 23:58:53 -0800 (PST)
Received: by elektron.atoom.net (Postfix, from userid 1000) id E25993FFCA; Wed, 9 Mar 2011 09:00:06 +0100 (CET)
Date: Wed, 9 Mar 2011 09:00:06 +0100
From: Miek Gieben <miek@miek.nl>
To: dnsext@ietf.org
Message-ID: <20110309080006.GA23957@miek.nl>
Mail-Followup-To: dnsext@ietf.org
References: <C99C3502.72B1%roy@nominet.org.uk> <alpine.LSU.2.00.1103082030190.5244@hermes-1.csi.cam.ac.uk> <72A22513B1644CFE9023189F93BFDD32@local>
MIME-Version: 1.0
Content-Type: multipart/signed; micalg=pgp-sha1; protocol="application/pgp-signature"; boundary="qMm9M+Fa2AknHoGS"
Content-Disposition: inline
In-Reply-To: <72A22513B1644CFE9023189F93BFDD32@local>
User-Agent: Vim/Mutt/Linux
X-Home: www.miek.nl
Subject: Re: [dnsext] CDS RRTYPE review - Comments period end Mar 29th
X-BeenThere: dnsext@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: DNS Extensions working group discussion list <dnsext.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/dnsext>, <mailto:dnsext-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/dnsext>
List-Post: <mailto:dnsext@ietf.org>
List-Help: <mailto:dnsext-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dnsext>, <mailto:dnsext-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 09 Mar 2011 07:58:58 -0000

[ Quoting George Barwood in "Re: [dnsext] CDS RRTYPE review - Co"... ]
> > Why not just use the child zone's SEP DNSKEY RRs for this purpose?
> 
> From the draft http://tools.ietf.org/html/draft-barwood-dnsop-ds-publish-01
> 
>   key, delaying the time at which an attacker can start cryptanalysis;

So this is the sole reason for adding this new type?

Regards,

--
 Miek