[dns-operations] Org Dnskey TTL

Andrew Sullivan ajs at shinkuro.com
Tue Apr 20 13:41:30 UTC 2010


On Tue, Apr 20, 2010 at 09:38:18PM +1000, Mark Andrews wrote:
> No.  The fetching of DNSKEY is unrelated to the number of child
> zone that are signed.  The DNSKEY is used to verify the contents
> of the ORG zone not its children.

Except that, of course, if you're validating your way up the chain you
will validate .org more often as more zones inside it are signed, no?

A

-- 
Andrew Sullivan
ajs at shinkuro.com
Shinkuro, Inc.



More information about the dns-operations mailing list