Discussion:
[Opendnssec-user] state of Automated DS management RFC 7344 support?
PGNet Dev
2017-01-04 01:20:45 UTC
Permalink
This post

https://lists.opendnssec.org/pipermail/opendnssec-user/2016-September/003661.html

suggests DNSSEC automation using CDS/CDNSKEY publication is planned for ODS

"Automated DS management such as described in RFC 7344 is on our roadmap of OpenDNSSEC 2.x (probably 2.2 or 2.3)."

In current ODS head, which builds as

Version 2.1.0-dev

there's still no mention of it, and @github, I don't yet see any other related dev branch.

With Gandi (at least -- maybe others as well) having now deployed an 'experimental', available for testing, implementation of

https://datatracker.ietf.org/doc/draft-ietf-regext-dnsoperator-to-rrr-protocol/

and Bind, KnotDNS & PowerDNS all providing CDS / CDNSKEY record publication/support (admittedly, untested yet against Gandi, in my case), it'd be useful to start working with ODS in the mix as well.

Is there a relevant dev branch yet available?
PGNet Dev
2017-01-04 04:28:38 UTC
Permalink
Post by PGNet Dev
Is there a relevant dev branch yet available?
Took a bit to track down, but for anyone else interested, this issue
looks like the most recent:

https://issues.opendnssec.org/browse/OPENDNSSEC-862

Loading...