<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Deliberately Invalidatable Root Zone</title>
	<atom:link href="http://www.forsberg.eu/2010/01/29/deliberately-invalidatable-root-zone/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.forsberg.eu/2010/01/29/deliberately-invalidatable-root-zone/</link>
	<description></description>
	<lastBuildDate>Thu, 08 Apr 2010 18:41:29 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
	<item>
		<title>By: LGForsberg</title>
		<link>http://www.forsberg.eu/2010/01/29/deliberately-invalidatable-root-zone/comment-page-1/#comment-3343</link>
		<dc:creator>LGForsberg</dc:creator>
		<pubDate>Fri, 29 Jan 2010 13:24:32 +0000</pubDate>
		<guid isPermaLink="false">http://www.forsberg.eu/?p=571#comment-3343</guid>
		<description>Thanks Patrik! 

I think my brain already halted while I wrote this last night. I made a &quot;NoNo&quot; and altered the post to better fit the truth.

Regards,
LG</description>
		<content:encoded><![CDATA[<p>Thanks Patrik! </p>
<p>I think my brain already halted while I wrote this last night. I made a &#8220;NoNo&#8221; and altered the post to better fit the truth.</p>
<p>Regards,<br />
LG</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Patrik Wallström</title>
		<link>http://www.forsberg.eu/2010/01/29/deliberately-invalidatable-root-zone/comment-page-1/#comment-3342</link>
		<dc:creator>Patrik Wallström</dc:creator>
		<pubDate>Fri, 29 Jan 2010 13:01:31 +0000</pubDate>
		<guid isPermaLink="false">http://www.forsberg.eu/?p=571#comment-3342</guid>
		<description>A correction here is needed. The root is currently signed with a fully valid key. It is the public key that is currently published as DURZ that is broken &quot;beyond recognition&quot;. The purpose of the DURZ is that you don&#039;t want people to be able to use the key for any validation whatsoever until the DNSSEC in root is considered as being in production. When that happens, the valid key is of course being published in the zone.</description>
		<content:encoded><![CDATA[<p>A correction here is needed. The root is currently signed with a fully valid key. It is the public key that is currently published as DURZ that is broken &#8220;beyond recognition&#8221;. The purpose of the DURZ is that you don&#8217;t want people to be able to use the key for any validation whatsoever until the DNSSEC in root is considered as being in production. When that happens, the valid key is of course being published in the zone.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
