[Public Comments] NCSG Comment on KSK Rollover Draft
Collin Kurre
collin at ARTICLE19.ORG
Thu Mar 22 09:44:30 EET 2018
Hi Louise, all,
Thanks a lot to the drafting team for putting this comment together—it’s concise, productive, and with a concrete recommendation. Well done!
I’ve added a couple suggestions to clarify language in places, as well as suggested shifting a couple sentences around so that your idea about getting users involved in knowing whether or not their local operator is rollover-ready is fully explained in one paragraph.
Hope this helps!
All the best,
Collin
Collin Kurre
Digital Programme
PGP Fingerprint:
C8E9 0123 A256 06E6 1471 53C5 5A7F 3E06 61CC 0603
<http://www.article19.org/> <http://www.article19.org/>
> On Mar 22, 2018, at 6:08 AM, Michael J. Oghia <mike.oghia at gmail.com> wrote:
>
> +1 from me too, thanks for this! I just added a few formatting and grammar edits.
>
> Best,
> -Michael
>
> On Wed, Mar 21, 2018 at 11:24 PM, Rafik Dammak <rafik.dammak at gmail.com <mailto:rafik.dammak at gmail.com>> wrote:
> Hi,
>
> Thanks Louise for sharing the draft and to the team for the work done with this comment. It is a good example of collaborative work for drafting comment and sharing the burden between several volunteers. as Policy Committee Chair, I encourage such approach for public comment for those volunteering.
> @all please review the draft and share your comments, the google doc is in suggestion mode.
>
> Best,
>
> Rafik
>
>
> 2018-03-22 3:23 GMT+09:00 Louise Marie Hurel <louise.marie.hsd at gmail.com <mailto:louise.marie.hsd at gmail.com>>:
> Hi all,
>
> Comments on the Plan to Restart the Root Key Signing Key (KSK) Rollover Process opened early February this year <https://www.icann.org/public-comments/ksk-rollover-restart-2018-02-01-en>. For those who have not been following the process that closely, KSK serves as a trust anchor for DNSSEC and was last (and for the first time) signed in 2010. ICANN had scheduled to implement a new key in October. However, they decided to postpone the signing of new cryptographic keys for the DNS after finding that the resolvers used by ISPs and network operators were still not ready and there's a need for more data in prepping for it.
>
> While the comment is narrow and highly technical in its scope, the overall idea of the process can be read as taking the next step in consolidating a way of periodically changing keys -- thus enhancing security and resilience in the DNS.
>
> Tomslin, Dina and I have worked on this draft <https://docs.google.com/document/d/1VNxn4UJlk8z196Kz56ucAdgyWp0ua9NmdHexRE1Wkhc/edit> and would be happy to get more comments edits, suggestions on this. Feel free to jump in.
>
> For more info, see here <https://www.icann.org/news/announcement-2017-09-27-en> and here <https://www.icann.org/en/system/files/files/plan-continuing-root-ksk-rollover-01feb18-en.pdf>.
>
> All the best,
>
> Louise Marie Hurel
> Cybersecurity Project Coordinator | Igarapé Institute
> London School of Economics (LSE) Media and Communications (Data and Society)
> Skype: louise.dias
> +44 (0) 7468 906327 <tel:+44%207468%20906327>
> l.h.dias at lse.ac.uk <mailto:l.h.dias at lse.ac.uk>
> louise.marie.hsd at gmail.com <mailto:louise.marie.hsd at gmail.com>
>
>
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.ncsg.is/pipermail/ncsg-discuss/attachments/20180322/2b2c5090/attachment.htm>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 833 bytes
Desc: Message signed with OpenPGP using GPGMail
URL: <http://lists.ncsg.is/pipermail/ncsg-discuss/attachments/20180322/2b2c5090/attachment.sig>
More information about the Ncsg-discuss
mailing list