ietf-dkim
[Top] [All Lists]

Re: [ietf-dkim] Delegating responsibility: a make vs. buy design decision

2006-08-25 10:11:46
Stephen Farrell wrote:


Where the delagatee supplies a public key to the delegator then its
quite likely that that public key will never get updated. That's a bad
thing.
But that's not the only form of delegation provided by -base.  It's also
possible for the delegator to publish NS records pointing
_domainkey.delegator.org at name servers managed by the delegatee, and
allowing the delegatee to publish (and update) key records there.  It's
also possible for the delegator to have multiple delegatees, by
publishing NS records for subdomains of the _domainkey domain to
multiple delegatees (which would then use dotted selector names).

The objection to this in favor of Delegated Signing Domains is that
delegators may not have the tools to publish NS records for subdomains.

-Jim

_______________________________________________
NOTE WELL: This list operates according to 
http://mipassoc.org/dkim/ietf-list-rules.html

<Prev in Thread] Current Thread [Next in Thread>