You have said you have been thinking of a DNSSEC2 proposal for a while, that your protocol differs in multiple ways and that it is easier to implement. Given this you should be able to concretely articulate how your…
Online signing and white lies are already in DNSSEC. What you've described so far doesn't seem to be different to the status quo. Even deprecation of older cryptographic signatures is being worked through at the moment.
> It is a selling point in that it simplifies the protocol, making it easier to implement. In the current protocol the only difference between offline and online signing is in how authoritative servers are implemented.…
Having no support for offline signing in and of itself isn't a selling point. What else does your approach have to offer?
You have said you have been thinking of a DNSSEC2 proposal for a while, that your protocol differs in multiple ways and that it is easier to implement. Given this you should be able to concretely articulate how your…
Online signing and white lies are already in DNSSEC. What you've described so far doesn't seem to be different to the status quo. Even deprecation of older cryptographic signatures is being worked through at the moment.
> It is a selling point in that it simplifies the protocol, making it easier to implement. In the current protocol the only difference between offline and online signing is in how authoritative servers are implemented.…
Having no support for offline signing in and of itself isn't a selling point. What else does your approach have to offer?