wrt joao damas' DLV talk on wednesday

Randy Bush randy at psg.com
Tue Jun 13 18:55:38 UTC 2006


> With the current trust policy, it seems to me that DLV is a
> bootstrap mechanism intended to promote bottom-up pressure for
> DNSSEC deployment, and to give people a chance to get to grips
> with things like key rollover and zone signing.

well, unlike ipv6 marketing efforts, at least it does not create
an unrecoverable mess in routing.

> It's a frog dressed up as a chicken which is being rolled out
> because people are fed up waiting for an egg.
> 
> In that context, perhaps it doesn't need to scale very far.

perhaps the bottom line is whether it makes us more vulnerable.
while an incorrectly secured zone is arguably no worse than one
which is not secured, it seems to create a focus for attack.

but what leaves me wondering is why this is all so difficult.
why can isc not simply say "we plan to vet zones as follows:.
and we plan to manage maintenance of key rollover as follows:
etc.?"

randy




More information about the NANOG mailing list