Re: [DNSOP] [dnsext] Why ZSK rollover is a Bad Idea (tm)

Joe Abley <jabley@hopcount.ca> Wed, 07 October 2009 14:35 UTC

Return-Path: <jabley@hopcount.ca>
X-Original-To: dnsop@core3.amsl.com
Delivered-To: dnsop@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id 822003A6939 for <dnsop@core3.amsl.com>; Wed, 7 Oct 2009 07:35:08 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.599
X-Spam-Level:
X-Spam-Status: No, score=-2.599 tagged_above=-999 required=5 tests=[BAYES_00=-2.599]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Kx0P6rxOWg3l for <dnsop@core3.amsl.com>; Wed, 7 Oct 2009 07:35:07 -0700 (PDT)
Received: from monster.hopcount.ca (monster.hopcount.ca [216.235.14.38]) by core3.amsl.com (Postfix) with ESMTP id D70993A6AA1 for <dnsop@ietf.org>; Wed, 7 Oct 2009 07:35:07 -0700 (PDT)
Received: from [193.0.27.97] (helo=dhcp-27-97.ripemtg.ripe.net) by monster.hopcount.ca with esmtpsa (TLSv1:AES128-SHA:128) (Exim 4.69 (FreeBSD)) (envelope-from <jabley@hopcount.ca>) id 1MvXc9-000Hi9-Oo; Wed, 07 Oct 2009 14:36:42 +0000
Mime-Version: 1.0 (Apple Message framework v1076)
Content-Type: text/plain; charset="us-ascii"; format="flowed"; delsp="yes"
From: Joe Abley <jabley@hopcount.ca>
In-Reply-To: <005603A4-31C0-49E0-894F-3FAEB38D7D92@dnss.ec>
Date: Wed, 07 Oct 2009 15:35:34 +0100
Content-Transfer-Encoding: 7bit
Message-Id: <DA50F4C7-6BB2-4CE1-AE4C-AF9392290EDF@hopcount.ca>
References: <1C586E51-D77C-406C-9B89-47276A9B41B2@ICSI.Berkeley.EDU> <p06240812c6f160ac1fb2@10.20.30.158> <d3aa5d00910061408y191bf863p48a6ec703553b67e@mail.gmail.com> <FB20C78E-3A72-409C-8406-2B8A00923783@NLnetLabs.nl> <712BBDEE-25FF-4E2E-A9E5-49E49162D41D@hopcount.ca> <005603A4-31C0-49E0-894F-3FAEB38D7D92@dnss.ec>
To: Roy Arends <roy@dnss.ec>
X-Mailer: Apple Mail (2.1076)
Cc: Eric Rescorla <ekr@rtfm.com>, Nicholas Weaver <nweaver@icsi.berkeley.edu>, dnsop WG <dnsop@ietf.org>, Paul Hoffman <paul.hoffman@vpnc.org>
Subject: Re: [DNSOP] [dnsext] Why ZSK rollover is a Bad Idea (tm)
X-BeenThere: dnsop@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/dnsop>, <mailto:dnsop-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/dnsop>
List-Post: <mailto:dnsop@ietf.org>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dnsop>, <mailto:dnsop-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 07 Oct 2009 14:35:08 -0000

On 2009-10-07, at 15:21, Roy Arends wrote:

> I find it worrying that folks intend to test or practice operational  
> procedures by doing it often on a live production system. What if  
> that test or practice fails? "Whoops, we were testing it on the live  
> system, we failed, good thing we called it a test"

I would find that worrying too. I was talking about exercising  
production machinery, not testing it. There's a difference.


Joe