nanog mailing list archives

Re: America takes over DNS


From: David Conrad <drc () virtualized org>
Date: Sun, 1 Apr 2007 08:35:02 -0700


Hi,

On Apr 1, 2007, at 6:54 AM, J. Oquendo wrote:
Summary:

Confusion resulting from hearsay and extrapolations.

The "key-signing key" signs the zone key, which is held by VeriSign.

Except that the root zone hasn't been signed and there are no plans I am aware of do so (and I think I'd probably know). In one possible scenario, VeriSign would hold the zone signing key which would be signed by the key signing key. Who holds the KSK hasn't been established.

However, in reality, nothing would change. Even if the root were to be signed, who signs it doesn't really matter -- the USG already must approve any changes made to the root zone.

Rgds,
-drc


Current thread: