[dns-operations] DNSSEC at ICANN: still no check?

Chris Thompson cet1 at cam.ac.uk
Tue Jan 21 11:13:58 UTC 2014


On Jan 20 2014, Matthew Pounsett wrote:

>On Jan 20, 2014, at 11:37 , 🔒 Roy Arends <roy at dnss.ec> wrote:
>
>> The problem is indeed the absence of type NS in the type bit maps,
>> as you (and Peter van Dijk) showed in your previous mail.
>
>It’s hard to see from outside since its all the same NS set, but I suspect
>red. and nic.red. are separate zones, but that there is no delegation from
>red. to nic.red.  I’ve seen that mistake before.  With the same NS set it
>wouldn’t appear as a problem prior to signing.

But there shouldn't have been a "prior to signing" state for "red", should
there? "In the absence of validation" might be an explanation, though.

-- 
Chris Thompson               University of Cambridge Computing Service,
Email: cet1 at ucs.cam.ac.uk    Roger Needham Building, 7 JJ Thomson Avenue,
Phone: +44 1223 334715       Cambridge CB3 0RB, United Kingdom.



More information about the dns-operations mailing list