[dns-operations] signing a zone with NSEC3 records.

Olaf Kolkman olaf at NLnetLabs.nl
Fri Sep 11 19:36:31 UTC 2009


On Sep 11, 2009, at 9:32 PM, Olaf Kolkman wrote:

>
> On Sep 11, 2009, at 6:49 PM, David Conrad wrote:
>
>>
>> Only 30% of the queries reaching the root have DO=0 (and by  
>> implication any authority) at this point in time.
>
>
>
> When I looked at this when working on RIPE352 (http://www.ripe.net/docs/ripe-352.html 
>  see figure 2) this was not true.


Oh by the way. Although realities have changed somewhat the document  
also contains an analysis of size distributions of the answer packets  
(see figure 13 and 14).

That data and analysis may be relevant for the recent discusions about  
fragmentations and what type of packets cause it.

--Olaf


________________________________________________________

Olaf M. Kolkman                        NLnet Labs
                                        Science Park 140,
http://www.nlnetlabs.nl/               1098 XG Amsterdam

-------------- next part --------------
A non-text attachment was scrubbed...
Name: PGP.sig
Type: application/pgp-signature
Size: 235 bytes
Desc: This is a digitally signed message part
URL: <https://lists.dns-oarc.net/pipermail/dns-operations/attachments/20090911/798c4e2d/attachment.sig>


More information about the dns-operations mailing list