[dns-operations] signing a zone with NSEC3 records.

Stephane Bortzmeyer bortzmeyer at nic.fr
Thu Sep 10 09:19:56 UTC 2009


On Thu, Sep 10, 2009 at 06:41:37PM +1000,
 Mark Andrews <marka at isc.org> wrote 
 a message of 32 lines which said:

> So what?  Blocking AXFR does nothing for security though most
> security consultants will say that it does.

BTW, zone transfer fails on every authoritative name server of
isc.org.




More information about the dns-operations mailing list