The problem with public keys is not distribution... The distributions machanisms we have now work fine. it's getting people to generate validate and use them. joelja On Thu, 11 Sep 2003 Valdis.Kletnieks@vt.edu wrote: > On Thu, 11 Sep 2003 22:27:25 EDT, Sergey Babkin <babkin@bellatlantic.net> said: > > Hello, > > > > I think that I've found an easy way to distribute the public keys: > > put them into DNS. The records would look like: > > Go to: > > http://search.ietf.org/ > > query 'dns public keys' > > Of particular interest: > > For SSH public keys: http://www.ietf.org/internet-drafts/draft-ietf-secsh-dns-05.txt > > IPSEC keying: http://www.ietf.org/internet-drafts/draft-ietf-ipseckey-rr-07.txt > > See also RFCs 2536-2539, and all the other DNSSEC RFCs. > > -- -------------------------------------------------------------------------- Joel Jaeggli Unix Consulting joelja@darkwing.uoregon.edu GPG Key Fingerprint: 5C6E 0104 BAF0 40B0 5BD3 C38B F000 35AB B67F 56B2