[dns-operations] Lack of tlsa support

Richard Lamb richard.lamb at icann.org
Mon Jun 1 21:22:09 UTC 2015


Thank you. That’s wonderful. –Rick


From: dns-operations [mailto:dns-operations-bounces at dns-oarc.net] On Behalf Of Kumar Ashutosh
Sent: Thursday, May 28, 2015 1:17 AM
To: dns-operations
Subject: Re: [dns-operations] Lack of tlsa support

JFYI, On the Server software side, Windows DNS Server has added support for TLSA records in the latest previews.

Thanks
Ashu
Program Manager | Windows Networking| DNS & SDN

From: dns-operations [mailto:dns-operations-bounces at dns-oarc.net] On Behalf Of Shumon Huque
Sent: Thursday, May 28, 2015 02:26
To: Warren Kumari
Cc: dns-operations
Subject: Re: [dns-operations] Lack of tlsa support

On Wed, May 27, 2015 at 3:59 PM, Shumon Huque <shuque at gmail.com<mailto:shuque at gmail.com>> wrote:


Here's a transcript of my attempt to query all the NS addresses at accountant for TLSA records (from one location, a datacenter in New Jersey). Quick summary: no response/timeout from all the IPv4 addresses, correct NODATA answers from all the IPv6 addresses. Hmm (and no, the machine originating the queries has working IPv4 and can query other records successfully):

Actually, I was wondering why those answers are NODATA rather than NXDOMAIN since presumably there aren't other record types at the name I queried. It looks like this is because this zone is in the controlled interruption mode (it has a wildcard at the apex for A, MX, etc).

Shumon Huque.

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.dns-oarc.net/pipermail/dns-operations/attachments/20150601/a5c8e6e6/attachment.html>


More information about the dns-operations mailing list