You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Sent in reponse to mailing list:
That language can be more precise. DS records enforce that the DNSKEY RRset is
located at the apex of the zone. There is no way around that.
It is true that different authoritative servers may serve different versions
of the DNSKEY RRset provided that all keys that are used to signed the zone
(ZSK) are in all copies of the DNSKEY RRset. So in practice this does not
avoid the need to coordinate in a multi-signer setup.
Issue by Ben Schwartz:
I don't think this is true. I would agree that it requires all DNSKEY
RRsets to cover the same set of algorithms.
The text was updated successfully, but these errors were encountered: