<html><head>
<meta content="text/html; charset=UTF-8" http-equiv="Content-Type">
</head><body text="#000000" bgcolor="#FFFFFF"><br>
<br>
<blockquote style="border: 0px none;"
cite="mid:CAHw9_iLdGnkmErvoVHhj41fswM6+5yj0tdxrSj17KdhzqTyGrw@mail.gmail.com"
type="cite">
<div style="margin:30px 25px 10px 25px;" class="__pbConvHr"><div
style="display:table;width:100%;border-top:1px solid
#EDEEF0;padding-top:5px"> <div
style="display:table-cell;vertical-align:middle;padding-right:6px;"><img
photoaddress="warren@kumari.net" photoname="Warren Kumari"
src="cid:part1.08040900.05000201@redbarn.org" name="postbox-contact.jpg"
width="25px" height="25px"></div> <div
style="display:table-cell;white-space:nowrap;vertical-align:middle;width:100%">
<a moz-do-not-send="true" href="mailto:warren@kumari.net"
style="color:#737F92
!important;padding-right:6px;font-weight:bold;text-decoration:none
!important;">Warren Kumari</a></div> <div
style="display:table-cell;white-space:nowrap;vertical-align:middle;">
<font color="#9FA2A5"><span style="padding-left:6px">Thursday,
November 27, 2014 1:11 PM</span></font></div></div></div>
<div style="color:#888888;margin-left:24px;margin-right:24px;"
__pbrmquotes="true" class="__pbConvBody">... and Mark Andrews, Paul
Hofmann, Paul Wouters, myself and a few others (who I embarrassing
enough have forgotten) are planning on writing a "zone signature" draft
(I have an initial version in an edit buffet). The 50,000 meter view is:<div>Sort
all the records in canonical order (including glue)</div><div>Cryptographicly
sign this</div><div>Stuff the signature in a record</div><div><br></div><div>This
allows you to verify that you have the full and complete zone (.de...)
and that it didn't get corrupted in transfer.</div>
<div>This solves a different, but related issue.<br></div>
</div>
</blockquote>
<br>
would this draft change the setting of the AA bit on an secondary
server's responses, or make it unwilling to answer under some
conditions? right now there is no dependency, AA is always set. but if
we're going to make it conditional, then it should be conditioned on the
signatures matching all the way up-chain to a trust anchor, which would
require an authority server to also contain a validator and be able to
make iterative queries. so, i wonder about the use case for your draft.<br>
<br>
<div class="moz-signature">-- <br>Paul Vixie<br>
</div>
</body></html>