[Dnssec-deployment] Domain registrars with easy DNSSEC interface?

Michael Richardson mcr at sandelman.ca
Tue Jan 17 12:40:12 EST 2012


>>>>> "Dave" == Dave Lawrence <tale at dd.org> writes:
    >> On Jan 17, 2012, at 8:55 AM, Bill Owens wrote:
    >>> I can see how it would be much more convenient having the same
    >>> organization offer both registrar and DNS hosting services,
    >>> since it allows the user to be out of the loop for installation
    >>> of the DS record,

    Dave> Dan York writes:
    >> Exactly.  For someone who has recently heard of DNSSEC and wants
    >> to "sign their domain", a combined registrar/DNS host can make it
    >> simple.

    Dave> As would be an official recognition of the role of DNS hosting
    Dave> provider, so that a trust relationship can be established
    Dave> between them and the registrar.

Are you thinking about such a thing as the ZSK / KSK split?
Are you thinking that the zone owner might retain the KSK privately,
while having the DNS hosting provider retain the ZSK?

Or is this more about who to call when there is a problem?

-- 
]       He who is tired of Weird Al is tired of life!           |  firewalls  [
]   Michael Richardson, Sandelman Software Works, Ottawa, ON    |net architect[
] mcr at sandelman.ottawa.on.ca http://www.sandelman.ottawa.on.ca/ |device driver[
   Kyoto Plus: watch the video <http://www.youtube.com/watch?v=kzx1ycLXQSE>
	               then sign the petition. 


More information about the Dnssec-deployment mailing list