[Opendnssec-user] OpenDNSSEC, HSM and key ceremony

Antoin Verschuren Antoin.Verschuren at sidn.nl
Fri Jun 11 09:13:42 UTC 2010


SO what's the use of the ICANN key ceremony then, when OpenDNSSEC can do an unattended KSK key rollover at will ?

Antoin Verschuren

Technical Policy Advisor SIDN
Utrechtseweg 310, PO Box 5022, 6802 EA Arnhem, The Netherlands

P: +31 26 3525500  F: +31 26 3525505  M: +31 6 23368970
mailto:antoin.verschuren at sidn.nl  xmpp:antoin at jabber.sidn.nl  http://www.sidn.nl/



> -----Original Message-----
> From: opendnssec-user-bounces at lists.opendnssec.org [mailto:opendnssec-
> user-bounces at lists.opendnssec.org] On Behalf Of Jakob Schlyter
> Sent: Friday, June 11, 2010 11:09 AM
> To: Antoin Verschuren
> Cc: Open DNSSEC List
> Subject: Re: [Opendnssec-user] OpenDNSSEC, HSM and key ceremony
>
> On 11 jun 2010, at 11.02, Antoin Verschuren wrote:
>
> > I wonder how ICANN or .se is doing this with OpenDNSSEC.
>
> OpenDNSSEC has currently no support for offline keys, so both ICANN and
> .SE are most likely using online KSK and ZSK.
>
>       jakob
>
> --
> Jakob Schlyter
> Kirei AB - http://www.kirei.se/
>
> _______________________________________________
> Opendnssec-user mailing list
> Opendnssec-user at lists.opendnssec.org
> https://lists.opendnssec.org/mailman/listinfo/opendnssec-user



More information about the Opendnssec-user mailing list