[dns-operations] signing a zone with NSEC3 records.
Olaf Kolkman
olaf at NLnetLabs.nl
Fri Sep 11 19:36:31 UTC 2009
On Sep 11, 2009, at 9:32 PM, Olaf Kolkman wrote:
>
> On Sep 11, 2009, at 6:49 PM, David Conrad wrote:
>
>>
>> Only 30% of the queries reaching the root have DO=0 (and by
>> implication any authority) at this point in time.
>
>
>
> When I looked at this when working on RIPE352 (http://www.ripe.net/docs/ripe-352.html
> see figure 2) this was not true.
Oh by the way. Although realities have changed somewhat the document
also contains an analysis of size distributions of the answer packets
(see figure 13 and 14).
That data and analysis may be relevant for the recent discusions about
fragmentations and what type of packets cause it.
--Olaf
________________________________________________________
Olaf M. Kolkman NLnet Labs
Science Park 140,
http://www.nlnetlabs.nl/ 1098 XG Amsterdam
-------------- next part --------------
A non-text attachment was scrubbed...
Name: PGP.sig
Type: application/pgp-signature
Size: 235 bytes
Desc: This is a digitally signed message part
URL: <https://lists.dns-oarc.net/pipermail/dns-operations/attachments/20090911/798c4e2d/attachment.sig>
More information about the dns-operations
mailing list