Skip to main content

Last Call Review of draft-ietf-dnsext-dnssec-rsasha256-
review-ietf-dnsext-dnssec-rsasha256-secdir-lc-zeilenga-2009-09-18-00

Request Review of draft-ietf-dnsext-dnssec-rsasha256
Requested revision No specific revision (document currently at 14)
Type Last Call Review
Team Security Area Directorate (secdir)
Deadline 2009-09-22
Requested 2009-09-10
Authors Jelte Jansen
I-D last updated 2009-09-18
Completed reviews Secdir Last Call review of -?? by Kurt Zeilenga
Assignment Reviewer Kurt Zeilenga
State Completed
Request Last Call review on draft-ietf-dnsext-dnssec-rsasha256 by Security Area Directorate Assigned
Completed 2009-09-18
review-ietf-dnsext-dnssec-rsasha256-secdir-lc-zeilenga-2009-09-18-00
I have reviewed this document as part of the security directorate's  


ongoing effort to review all IETF documents being processed by the  


IESG.  These comments were written primarily for the benefit of the  


security area directors.  Document editors and WG chairs should treat  


these comments just like any other last call comments.






This document details how to produce RSA/SHA-512 and RSA/SHA-256  


DNSKEY and RRSIG RRs in DNS.






I find the document more than adequately discusses and addresses  


security considerations.






I do note that the document appears to place an additional  


recommendation upon implementors of DNSSEC (in Section 5.1) yet does  


not "update" any DNSSEC specification.   It may be appropriate for  


this I-D to "update" (upon approval/publication) DNSSEC specifications.




Regards, Kurt