[dns-operations] OARC's Open DNSSEC Validating Resolver project

David Coulthart davec at columbia.edu
Fri Nov 7 14:59:14 UTC 2008

On Nov 5, 2008, at 9:37 AM, David Coulthart wrote:
> I also wonder how you're performing key rollover management; this is  
> a big issue concerning me about changing my own recursive resolvers  
> to perform DNSSEC validation.  Of the seven keys you include as  
> trust anchors, I haven't been able to find mailing lists for  
> announcing key rollover for four of them (.museum, .bg, .cz, & .pr,  
> though I contacted the PR NIC & they said they're currently  
> revamping their mailing list site).  How do you plan on making sure  
> these keys don't expire?

Thank you to everyone for your feedback.

I also wanted to post a followup about the PR NIC.  I received  
notification from them that their key announcement mailing list is now  
working and you can subscribe to it at:


Dave C.

More information about the dns-operations mailing list