[dns-operations] Fun with DNAME and DNSSEC

Wessels, Duane dwessels at verisign.com
Tue Jan 28 22:26:43 UTC 2014


On Jan 28, 2014, at 7:51 AM, Tony Finch <dot at dotat.at> wrote:

> The Verisign Labs DNSSEC debugger does quite well, though it does not
> understand that CNAME records synthesized from DNAME records do not have
> RRSIG records.


Hi Tony,

You should find that the Debugger now properly recognizes the DNAME record.
It previously only used the DNAME record when the owner name was equal to
the zone name.

Duane W.
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 495 bytes
Desc: Message signed with OpenPGP using GPGMail
URL: <https://lists.dns-oarc.net/pipermail/dns-operations/attachments/20140128/0db1ce40/attachment.sig>


More information about the dns-operations mailing list