|
|||||
|
Twitter
Recent Article Posts
Recent Comments
Month Archive
Login
|
Re: Re: DNSSEC-Deployment Group Now Discussing Distributed Root Signing
by
Brenden Kuerbis
In the post you refer to, the author is actually making a clear distinction between two totally different applications of digital signing technology. The first is a scenario that involves multiple KSKs used to sign the root ZSK (which the poster is saying would be "somewhat horrific" because of coordination issues, but as noted by the chair of SSAC in another post, this option has never been fully explored). The second is a threshold signature, which could use a single KSK/signature function that is distributed in some fashion among relevant parties (which the poster said is the "appropriate technology" if "you want multiple entities to be responsible for the signatures on the root zone"). An important difference that is easy to overlook.
|
Help support our work
Make a secure, tax deductible donation online today.
What we're reading
Upcoming Events
Who's Reading IGP Blog?
Wowzio grab this · technology blog |
|||
|
|
|||||

