Re: [DNSOP] Signing the root == end of ITAR?

Jim Reid <jim@rfc1035.com> Wed, 07 October 2009 15:38 UTC

Return-Path: <jim@rfc1035.com>
X-Original-To: dnsop@core3.amsl.com
Delivered-To: dnsop@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id 7FA1B28C0F8 for <dnsop@core3.amsl.com>; Wed, 7 Oct 2009 08:38:23 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.855
X-Spam-Level:
X-Spam-Status: No, score=-1.855 tagged_above=-999 required=5 tests=[AWL=0.745, BAYES_00=-2.599]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id aUFXQUUuJ1Nc for <dnsop@core3.amsl.com>; Wed, 7 Oct 2009 08:38:22 -0700 (PDT)
Received: from hutch.rfc1035.com (hutch.rfc1035.com [195.54.233.70]) by core3.amsl.com (Postfix) with ESMTP id 918873A6902 for <dnsop@ietf.org>; Wed, 7 Oct 2009 08:38:22 -0700 (PDT)
Received: from dhcp-25-210.ripemtg.ripe.net (dhcp-25-210.ripemtg.ripe.net [193.0.25.210]) (using TLSv1 with cipher AES128-SHA (128/128 bits)) (No client certificate requested) (Authenticated sender: jim) by hutch.rfc1035.com (Postfix) with ESMTPSA id 0120F1542060; Wed, 7 Oct 2009 16:39:58 +0100 (BST)
Message-Id: <3099E8AC-F609-4B6B-AEFD-2B5635787AF9@rfc1035.com>
From: Jim Reid <jim@rfc1035.com>
To: Stephane Bortzmeyer <bortzmeyer@nic.fr>
In-Reply-To: <20091007151353.GA11599@laperouse.bortzmeyer.org>
Content-Type: text/plain; charset="US-ASCII"; format="flowed"; delsp="yes"
Content-Transfer-Encoding: 7bit
Mime-Version: 1.0 (Apple Message framework v936)
Date: Wed, 07 Oct 2009 16:39:41 +0100
References: <B668D106-141E-48EB-8C2D-C4AC7C2EB4DD@dnss.ec> <20091007151353.GA11599@laperouse.bortzmeyer.org>
X-Mailer: Apple Mail (2.936)
Cc: dnsop@ietf.org, Roy Arends <roy@dnss.ec>
Subject: Re: [DNSOP] Signing the root == end of ITAR?
X-BeenThere: dnsop@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/dnsop>, <mailto:dnsop-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/dnsop>
List-Post: <mailto:dnsop@ietf.org>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dnsop>, <mailto:dnsop-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 07 Oct 2009 15:38:23 -0000

On 7 Oct 2009, at 16:13, Stephane Bortzmeyer wrote:

> As someone in the public (at the RIPE meeting) mentioned, the timeline
> presented by ICANN/Verisign said nothing about the inclusion of DS
> records in the root (remember that each KSK rollover will require the
> prior approbation, in writing, of the US government).

Dave Knight is due to talk about the ITAR in the DNS WG tomorrow. We  
might have more news then about how the ITAR might morph into the way  
for TLDs to lodge their KSKs with the signed root.