Skip to content

compare zones #102

@maertsen

Description

@maertsen

Implement an equivalent of ldns compare-zones, ideally including the ability of doing a comparison of the unsigned content between a signed version of a zone against its unsigned input.

Perhaps in a manner suggested by https://www.ietf.org/archive/id/draft-johani-tld-zone-pipeline-02.html#name-resulting-design-consequenc:

The requirement on being able to prove that no unsigned data has been modified during signing is most efficiently fullfilled by computing the ZONEMD checksum on the unsigned data after signing (i.e. the signed zone modulo the DNSSEC related records DNSKEY, RRSIG. NSEC, NSEC3, NSEC3PARAM, apex CDS and CDNSKEY) and comparing that to the ZONEMD checksum for the corresponding unsigned zone.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions