| 81 | | method to publish Trust Anchors (TAs) for islands of security in a |
|---|
| 82 | | repository independent of the island of security. This, in turn, has |
|---|
| 83 | | the potential for efficient TA management on the validator, as the |
|---|
| 84 | | validator can configure the TA for the DLV repository, instead of |
|---|
| | 81 | method to publish Trust Anchors (TAs) for islands of security |
|---|
| | 82 | <xref target="RFC4033"/> outside the delegation chain. This, in turn, |
|---|
| | 83 | has the potential for efficient TA management on the validator, as |
|---|
| | 84 | the validator can configure the TA for the DLV repository, instead of |
|---|
| 135 | | <!-- |
|---|
| 136 | | <t> |
|---|
| 137 | | [we should get two points accross. (1) zone admins have a choice in registry to use, val-admins have a choice in registry to trust. (2) all the scaling cruft.] |
|---|
| 138 | | </t> |
|---|
| 139 | | --> |
|---|
| 140 | | |
|---|
| 141 | | <!-- |
|---|
| 142 | | <t> |
|---|
| 143 | | <xref target="RFC4431">RFC 4431</xref> specified the DLV DNS |
|---|
| 144 | | Resource Record, introducing the concept of trust anchors outside |
|---|
| 145 | | the delegation chain. This allows zone-administrators to have |
|---|
| 146 | | their DNSSEC <xref target="RFC4033"/><xref target="RFC4034"/><xref |
|---|
| 147 | | target="RFC4035"/> signed zone secured independent of the DNSSEC |
|---|
| 148 | | status of the parent. The DLV trust anchor needs to be configured |
|---|
| 149 | | in a validator in order to allow this non-hierarchial trust |
|---|
| 150 | | validation. Though DLV was intended to be a temporary trust-chain ... |
|---|
| 151 | | </t> |
|---|
| 152 | | --> |
|---|
| 153 | | |
|---|
| 158 | | <list> |
|---|
| | 134 | A Security Aware Resolver sends requests with the DNSSEC-OK bit set, |
|---|
| | 135 | regardless of any configured TA. It expects the zone at a configured |
|---|
| | 136 | TA to be secured, and thus responses to contain DNSSEC records. |
|---|
| | 137 | </t> |
|---|
| | 138 | <t> |
|---|
| | 139 | When a Security Aware Resolver has no TAs configured for a requested |
|---|
| | 140 | name, and has one or more DLV-TAs configured, and receives a response for that name |
|---|
| | 141 | containing DNSSEC records, it sends a request for a DLVPTR to the highest point in the |
|---|
| | 142 | delegation chain that contained DNSSEC records. |
|---|
| | 143 | </t> |
|---|
| | 144 | <t> |
|---|
| | 145 | <list> |
|---|