[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: KSK-2017 SUAs



Adam, thanks for writing these. The texts look good to me with (or even without) Robert's changes.


On 9 September 2017 20:19:13 Robert Edmonds <edmonds@debian.org> wrote:

Adam D. Barratt wrote:
Hi,

It's not clear whether there will have been a stretch point release
before the KSK rollover in October, but there definitely won't have
been a jessie point release, and in any case we need to update unbound
in the next couple of days (to avoid new installs on stretch having
broken DNSSEC validation for the next month).

Assuming I've not missed any packages that have been updated, we need
four SUAs. I've included draft text for each below - review, comments
and suggestions welcome.

Hi, Adam:

Thanks for writing these! The text mostly looks good to me. The only nit
I have is that I would write "The keys used to authenticate the root DNS
zone" instead of "The keys used to [sign] the root DNS zone[s]".
Technically, there is a chain of signatures and the KSKs do not directly
sign the root zone, and there is only a singular root zone.

--
Robert Edmonds
edmonds@debian.org



Reply to: