[dns-operations] Signing of the ARPA zone

Mark Andrews marka at isc.org
Thu Mar 25 18:07:26 UTC 2010


In message <Prayer.1.3.2.1003251704090.12879 at hermes-2.csi.cam.ac.uk>, Chris Thompson writes:
> On Mar 25 2010, Michael Graff wrote:
> 
> >On 3/25/10 9:08 AM, Chris Thompson wrote:
> >
> >> I actually half expected this to happen
> >
> >I didn't.  If this is widespread, I will pull arpa from dlv for now.
> 
> My impression (e.g. from the CERN/cz incident) is that the bad state does
> self-correct before too long. (I said in my bind-bugs report that it might
> have something to do with the 1 hour TTL on dlv.isc.org entries, but the
> times quoted here for "arpa" now make me doubt that.)

The TTL will be related to the cached data under arpa.  When the
offending data clears the cache it will correct itself.  This is
likely to be the ttl of the DNSKEY, DS or negative DS cache entry.

> -- 
> Chris Thompson               University of Cambridge Computing Service,
> Email: cet1 at ucs.cam.ac.uk    New Museums Site, Cambridge CB2 3QH,
> Phone: +44 1223 334715       United Kingdom.
> _______________________________________________
> dns-operations mailing list
> dns-operations at lists.dns-oarc.net
> https://lists.dns-oarc.net/mailman/listinfo/dns-operations
-- 
Mark Andrews, ISC
1 Seymour St., Dundas Valley, NSW 2117, Australia
PHONE: +61 2 9871 4742                 INTERNET: marka at isc.org



More information about the dns-operations mailing list