Name: draft-laurie-dnssec-key-distribution-00
Title: Distributing Keys for DNSSEC
State: Active
Authors: Ben Laurie
Group: Individual Submissions (none)
Date: 2004-10-01
Until DNSSEC is fully deployed, so-called "islands of trust" will exist.
This will lead to a large number of keys with no method within DNSSEC to
manage the keys. This proposal seeks to address that issue using existing
mechanisms to allow cross-signing of root (i.e. roots of islands) keys.
This cross-signing of keys creates a non-hierarchical web of trust which
permits the efficient gathering and validation of trust anchors.
|
|
|