Gentoo Archives: gentoo-dev

From: Daniel Black <dragonheart@g.o>
To: gentoo-dev@l.g.o
Cc: matsuu@g.o
Subject: [gentoo-dev] RFC: dnssec root key trust anchor package
Date: Sat, 13 Nov 2010 09:45:38
Message-Id: 201011132047.45521.dragonheart@gentoo.org
1 In light of the dnssec root key signing there is the issue of how to get this
2 into default installs of operating systems. A number of programs that are
3 DNSSEC aware will need access to the dnssec root key. I see this has the same
4 problem that app-misc/ca-certificates solved and a net-dns/dnssec root package
5 should be created to install the root key.
6
7 I'm thinking this should install into /etc/dnssec/ which would contain the
8 root key in xml and a bind format (also used by unbound) along with the certs
9 and keys required to verify this. (source http://data.iana.org/root-anchors/)
10
11 Looking at what other distros are doing I have only found the debian bug (
12 http://bugs.debian.org/cgi-bin/bugreport.cgi?msg=5;bug=594911 ) which is
13 solving it for one package rather than for all DNSSEC root key users.
14
15 Looking at the ICANN proposals it seems this package will be updated every 2-5
16 years. Managing this as a distribution package will acheive a more consistant
17 rollover when this occurs compared to relying on users to manage their own
18 dnssec root download and operations.
19
20 Am I going about this the right way or is there a better way?
21
22 Daniel