Note that keys are not productional until announced
authorPeter Palfrader <peter@palfrader.org>
Sun, 14 Feb 2010 19:51:14 +0000 (20:51 +0100)
committerPeter Palfrader <peter@palfrader.org>
Sun, 14 Feb 2010 19:51:14 +0000 (20:51 +0100)
input/dsablog/2010/02/Securing_the_Debian_zones.mdwn

index b4f86d9..5ebffa5 100644 (file)
@@ -55,6 +55,10 @@ we can just put proper
 [DS records](http://en.wikipedia.org/wiki/List_of_DNS_record_types#DS)
 in the respective parent zone.
 
+Until we announce the first set of trust anchors on the mailinglist the
+keysets present in DNS should not be considered productional.  They can
+be changed at any time.
+
 See also:
 
 * [DNSSEC wikipedia page](http://en.wikipedia.org/wiki/Domain_Name_System_Security_Extensions),