[dns-operations] Signing of the ARPA zone

Chris Thompson cet1 at cam.ac.uk
Tue Mar 16 12:34:06 UTC 2010


On Mar 15 2010, I wrote:

>The servers that are delivering a signed "arpa" so far have DNSKEY/RRSIG
>records using algorithm RSASHA1 (5) rather than RSASHA256 (8). Has there
>been a change of plan in that respect?

Ah... today they (that's [ghiklm].root-servers.net so far) have switched
to an RSASHA256-signed version of "arpa".

There has to be story behind this... :-)

-- 
Chris Thompson               University of Cambridge Computing Service,
Email: cet1 at ucs.cam.ac.uk    New Museums Site, Cambridge CB2 3QH,
Phone: +44 1223 334715       United Kingdom.



More information about the dns-operations mailing list