From: Peter Palfrader Date: Sun, 14 Feb 2010 19:51:14 +0000 (+0100) Subject: Note that keys are not productional until announced X-Git-Url: https://git.adam-barratt.org.uk/?p=mirror%2Fdsa-wiki.git;a=commitdiff_plain;h=1c8d7a4924ba6fa98367215855c8ec626cc67efb Note that keys are not productional until announced --- diff --git a/input/dsablog/2010/02/Securing_the_Debian_zones.mdwn b/input/dsablog/2010/02/Securing_the_Debian_zones.mdwn index b4f86d9..5ebffa5 100644 --- a/input/dsablog/2010/02/Securing_the_Debian_zones.mdwn +++ b/input/dsablog/2010/02/Securing_the_Debian_zones.mdwn @@ -55,6 +55,10 @@ we can just put proper [DS records](http://en.wikipedia.org/wiki/List_of_DNS_record_types#DS) in the respective parent zone. +Until we announce the first set of trust anchors on the mailinglist the +keysets present in DNS should not be considered productional. They can +be changed at any time. + See also: * [DNSSEC wikipedia page](http://en.wikipedia.org/wiki/Domain_Name_System_Security_Extensions),