[dns-operations] Some DNSSEC trivia

Ralf Weber denic at eng.colt.net
Thu Jan 3 07:31:17 UTC 2008


Moin!

On Jan 3, 2008, at 01:13 , Mark Andrews wrote:
> 	Just about all of which can be completely automated.  The only
> 	thing that can't be is establishing the initial secure delegation.
>
> 	Key roll overs can be automated.  Re-signing has been automated.
> 	Updating of DS records in the parent zone can be automated.
>
> 	All it requires is the will to let it happen.  We have the
> 	building blocks to do it today.
There are building blocks and a lot can be automated, but there is AFAIK
no complete and simple solution for DNSSEC deployment. If DNSSEC was a
option in the zone configuration and deployment was nearly as easy as
normal DNS we could see more people giving it a try.

So long
-Ralf
---
Ralf Weber
Platform Infrastructure Manager
Colt Telecom GmbH
Herriotstrasse 4
60528 Frankfurt
Germany
DDI: +49 (0)69 56606 2780 Internal OneDial: 8 491 2780
Fax: +49 (0)69 56606 6280
Email: rw at colt.net
http://www.colt.net/

Data | Voice | Managed Services

*****************************************
COLT Telecom GmbH, Herriotstraße 4, 60528 Frankfurt/Main, Deutschland *
Tel +49 (0)69 56606 0 * Fax +49 (0)69 56606 2222 *
Geschäftsführer: Albertus Marinus Oosterom (Vors.), Rita Thies *
Amtsgericht Frankfurt/Main HRB 53898 * USt.-IdNr. DE 220 772 475





More information about the dns-operations mailing list