From 1c8d7a4924ba6fa98367215855c8ec626cc67efb Mon Sep 17 00:00:00 2001 From: Peter Palfrader Date: Sun, 14 Feb 2010 20:51:14 +0100 Subject: [PATCH] Note that keys are not productional until announced --- input/dsablog/2010/02/Securing_the_Debian_zones.mdwn | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/input/dsablog/2010/02/Securing_the_Debian_zones.mdwn b/input/dsablog/2010/02/Securing_the_Debian_zones.mdwn index b4f86d9..5ebffa5 100644 --- a/input/dsablog/2010/02/Securing_the_Debian_zones.mdwn +++ b/input/dsablog/2010/02/Securing_the_Debian_zones.mdwn @@ -55,6 +55,10 @@ we can just put proper [DS records](http://en.wikipedia.org/wiki/List_of_DNS_record_types#DS) in the respective parent zone. +Until we announce the first set of trust anchors on the mailinglist the +keysets present in DNS should not be considered productional. They can +be changed at any time. + See also: * [DNSSEC wikipedia page](http://en.wikipedia.org/wiki/Domain_Name_System_Security_Extensions), -- 2.20.1