[dns-operations] negative dnssec replies

Router Log logrouterlog at gmail.com
Sat Nov 26 13:10:57 UTC 2016


The signing of negative replies from dnssec enabled zones increase the size
of the zone data an the complexity dns. For the ease of use and
implementaion would it be a good idea that a dnssec enabled zone could
signal to a querier that it intends to send unsigned nxdomain replies? This
mechanism would have to be signed of course.
Kind Regards Peter Davies
peter.davies at esc.co.uk
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.dns-oarc.net/pipermail/dns-operations/attachments/20161126/78ba8999/attachment.html>


More information about the dns-operations mailing list