Internet Governance Project (IGP)
Twitter
Year Archive
Login
User name:
Password:
Remember me 
Re: Re: DNSSEC-Deployment Group Now Discussing Distributed Root Signing
by Brenden Kuerbis
In the post you refer to, the author is actually making a clear distinction between two totally different applications of digital signing technology. The first is a scenario that involves multiple KSKs used to sign the root ZSK (which the poster is saying would be "somewhat horrific" because of coordination issues, but as noted by the chair of SSAC in another post, this option has never been fully explored). The second is a threshold signature, which could use a single KSK/signature function that is distributed in some fashion among relevant parties (which the poster said is the "appropriate technology" if "you want multiple entities to be responsible for the signatures on the root zone"). An important difference that is easy to overlook.
Post comment:
Format Type: 
  Convert newlines
  Receive comment notifications for this article
Subject: 
   
insert bold tags insert italic tags insert underline tags insert strikethough tags insert link insert blockquote tags
Comment: 
Comment verification:

Please enter the text you see inside the graphic to post your comment:
This blog does not allow anonymous comments. Please provide your username and password along with your comment.
Login information:
Username: 
Password: 
If you would like to post contact information on your comment, please enter your information into the optional fields below:
Contact information:
URL:  example: http://yourdomain.com
   
Help support our work
What we're reading
Upcoming Events
View all Events
Who's Reading IGP Blog?