1 |
In light of the dnssec root key signing there is the issue of how to get this |
2 |
into default installs of operating systems. A number of programs that are |
3 |
DNSSEC aware will need access to the dnssec root key. I see this has the same |
4 |
problem that app-misc/ca-certificates solved and a net-dns/dnssec root package |
5 |
should be created to install the root key. |
6 |
|
7 |
I'm thinking this should install into /etc/dnssec/ which would contain the |
8 |
root key in xml and a bind format (also used by unbound) along with the certs |
9 |
and keys required to verify this. (source http://data.iana.org/root-anchors/) |
10 |
|
11 |
Looking at what other distros are doing I have only found the debian bug ( |
12 |
http://bugs.debian.org/cgi-bin/bugreport.cgi?msg=5;bug=594911 ) which is |
13 |
solving it for one package rather than for all DNSSEC root key users. |
14 |
|
15 |
Looking at the ICANN proposals it seems this package will be updated every 2-5 |
16 |
years. Managing this as a distribution package will acheive a more consistant |
17 |
rollover when this occurs compared to relying on users to manage their own |
18 |
dnssec root download and operations. |
19 |
|
20 |
Am I going about this the right way or is there a better way? |
21 |
|
22 |
Daniel |