Re: [DNSOP] draft-ietf-dnsop-dnssec-trust-history - discussion

"W.C.A. Wijngaards" <wouter@NLnetLabs.nl> Tue, 21 September 2010 09:20 UTC

Return-Path: <wouter@nlnetlabs.nl>
X-Original-To: dnsop@core3.amsl.com
Delivered-To: dnsop@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id AC6C73A696D for <dnsop@core3.amsl.com>; Tue, 21 Sep 2010 02:20:05 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.455
X-Spam-Level:
X-Spam-Status: No, score=-2.455 tagged_above=-999 required=5 tests=[AWL=0.145, BAYES_00=-2.599, NO_RELAYS=-0.001]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id X2aWDcWaRyW1 for <dnsop@core3.amsl.com>; Tue, 21 Sep 2010 02:20:04 -0700 (PDT)
Received: from open.nlnetlabs.nl (open.nlnetlabs.nl [IPv6:2001:7b8:206:1::1]) by core3.amsl.com (Postfix) with ESMTP id C98133A695C for <dnsop@ietf.org>; Tue, 21 Sep 2010 02:20:03 -0700 (PDT)
Received: from gary.nlnetlabs.nl (gary.nlnetlabs.nl [IPv6:2001:7b8:206:1:216:76ff:feb8:1853]) (authenticated bits=0) by open.nlnetlabs.nl (8.14.4/8.14.3) with ESMTP id o8L9KMNZ097432 (version=TLSv1/SSLv3 cipher=DHE-RSA-CAMELLIA256-SHA bits=256 verify=NO) for <dnsop@ietf.org>; Tue, 21 Sep 2010 11:20:25 +0200 (CEST) (envelope-from wouter@nlnetlabs.nl)
Message-ID: <4C9878D6.9070707@nlnetlabs.nl>
Date: Tue, 21 Sep 2010 11:20:22 +0200
From: "W.C.A. Wijngaards" <wouter@NLnetLabs.nl>
User-Agent: Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.9.2.9) Gecko/20100907 Fedora/3.1.3-1.fc13 Lightning/1.0b3pre Thunderbird/3.1.3
MIME-Version: 1.0
To: dnsop@ietf.org
References: <569C36E4-4F05-41B2-B0B8-A4B8228F13C9@googlemail.com> <p06240843c8b86ff53ffe@[10.20.30.158]> <4C9342C1.309@nlnetlabs.nl> <p06240855c8b93727b62f@[10.20.30.158]>
In-Reply-To: <p06240855c8b93727b62f@[10.20.30.158]>
X-Enigmail-Version: 1.1.2
Content-Type: text/plain; charset="ISO-8859-1"
Content-Transfer-Encoding: 7bit
X-Greylist: Sender succeeded SMTP AUTH, not delayed by milter-greylist-4.2.6 (open.nlnetlabs.nl [IPv6:2001:7b8:206:1::1]); Tue, 21 Sep 2010 11:20:25 +0200 (CEST)
Subject: Re: [DNSOP] draft-ietf-dnsop-dnssec-trust-history - discussion
X-BeenThere: dnsop@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/dnsop>, <mailto:dnsop-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/dnsop>
List-Post: <mailto:dnsop@ietf.org>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dnsop>, <mailto:dnsop-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 21 Sep 2010 09:20:05 -0000

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Hi,

Thanks for your comments and suggestions, and I'll go and make my
(software-vendor-specific-)pick from them.

Best regards,
   Wouter

On 09/17/2010 05:31 PM, Paul Hoffman wrote:
> No, I am sure we don't want to create a forced cross-dependency on
> https. But that is far from the only choice. I am only interested in
> the first case. I could care less about alternate DNSSEC roots, and
> the people I know who care about distribution of lower-in-the-tree
> trust anchors have enough control of the affected systems to deal
> with missed rollovers.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.10 (GNU/Linux)
Comment: Using GnuPG with Fedora - http://enigmail.mozdev.org/

iEYEARECAAYFAkyYeNYACgkQkDLqNwOhpPj/vwCfXlXMhhC8YhKc0aSgBCO+qGFf
za0AoIWKgxtWO6knZFA5f/ViT+/1ojTJ
=w+Fz
-----END PGP SIGNATURE-----