Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Algorithm Key Rollover support #22

Open
tobez opened this issue Aug 15, 2012 · 0 comments
Open

Algorithm Key Rollover support #22

tobez opened this issue Aug 15, 2012 · 0 comments

Comments

@tobez
Copy link
Owner

tobez commented Aug 15, 2012

Via Daniel Stirnimann:

  • there are multiple RRSIGs for every signed record
  • one or more DNSKEYs for some of those RRSIGs is missing
  • but there is at least one valid RRSIG for which a valid key is found,
    for every signed record

If so, then it might make sense to not consider this an error at all
(or maybe add a policy check that will make such cases into errors,
thus allowing the operator the degree of control you suggest, effectively).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant