[dns-operations] .Org DNSSEC key management policy feedback

David Conrad drc at virtualized.org
Sun Jun 21 14:50:47 UTC 2009


George,

On Jun 20, 2009, at 11:38 PM, George Barwood wrote:
> (2) "the public will need to update their validating resolvers with  
> the new public portion of the .ORG zone key."
>
> Surely not? Won't the .ORG DS record be published by IANA?

Yes, but until the root is signed, people will still need to update  
their trust anchors to reflect all the islands of trust, including the  
TLDs, they want to validated.

Regards,
-drc




More information about the dns-operations mailing list