From 4f1f5c2260806ee2d50f2a471510079330529fa8 Mon Sep 17 00:00:00 2001 From: Peter Palfrader Date: Sun, 14 Feb 2010 20:52:35 +0100 Subject: [PATCH] Different link for NSEC3 as nsec3.org is down --- input/dsablog/2010/02/Securing_the_Debian_zones.mdwn | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/input/dsablog/2010/02/Securing_the_Debian_zones.mdwn b/input/dsablog/2010/02/Securing_the_Debian_zones.mdwn index 5ebffa5..9cd3524 100644 --- a/input/dsablog/2010/02/Securing_the_Debian_zones.mdwn +++ b/input/dsablog/2010/02/Securing_the_Debian_zones.mdwn @@ -28,7 +28,7 @@ DNS infrastructure www) will follow at a later date. -We are using bind 9.6 for [NSEC3](http://www.nsec3.org/) support and +We are using bind 9.6 for [NSEC3](http://tools.ietf.org/html/rfc5155) support and [our](http://git.debian.org/?p=mirror/Net-DNS-SEC-Maint-Key.git) [fork](http://git.debian.org/?p=mirror/Net-DNS-SEC-Maint-Zone.git) of RIPE's @@ -42,7 +42,7 @@ We will use NSEC3RSASHA1 with key sizes of 1536 bits for the KSK and 1152 bits for the ZSK. Signature validity period will most likely be four weeks, with a one week signature publication period (cf. [RFC4641: DNSSEC Operational -Practices](http://www.ietf.org/rfc/rfc4641.txt)). +Practices](http://tools.ietf.org/html/rfc4641)). Zone keys rollovers will happen regularly and will not be announced in any specific way. Key signing key rollovers will probably be announced -- 2.20.1