I know this update has been some time in coming, and I apologise for
that, but the discussion about how DNSKEY/DS RRs should be submitted
caused us to re-evaluate our plans.
The plan is still, as suggested, in two stages. Firstly to sign ac.uk,
and after that to accept DS records for delegations.
We've hammered out some of the technical details for signing the zone,
and hope to start the internal trials soon.
We have also started to scope out the work for building a front-end for
creating and modifying delegations, which should hopefully answer some
of the comments made previously. This will, however, take a few months
as it will be a complete "portal" for managing your DNS delegations. It
is possible that we could accept DS records for a few trial sites by
email in an interim phase before it is ready, but I think we're unlikely
to "launch" a DNSSEC service until it is there.
Cheers,
Rob
|