Re: How to measure the impact of enabling DNSSEC?

2013-01-28 Thread Brian Kroth
Lawrence K. Chen, P.Eng. 2013-01-25 17:57: - Original Message - On Wed, Jan 23, 2013 at 11:38 AM, Augie Schwer wrote: On Tue, Jan 22, 2013 at 2:32 PM, Mark Andrews wrote: In message , Augie Schwer wri tes: Would measuring the number of SERVFAIL entries in the "query-errors"

Re: DNSSEC DS vs DNSKEY record publication order question (wrt key algorithm rollover)

2013-01-17 Thread Brian Kroth
Tony Finch 2013-01-17 12:02: Brian Kroth wrote: RFC 4035 sec 2.2 says There MUST be an RRSIG for each RRset using at least one DNSKEY of each algorithm in the zone apex DNSKEY RRset. The apex DNSKEY RRset itself MUST be signed by each algorithm appearing in the DS RRset located at the

Re: DNSSEC DS vs DNSKEY record publication order question (wrt key algorithm rollover)

2013-01-16 Thread Brian Kroth
Brian Paul Kroth 2013-01-15 23:19: Hello All, First, I'm not currently on the list, so please CC if me if you could. Let's try this again now that I'm on the list. Next, I've been working on some scripts to get KSK rotation semi-automated or at least alerting in our environment and I've got