[dns-operations] Strange behavior of google public resolver

Taras Heichenko tasic at hostmaster.ua
Thu Apr 18 11:07:55 UTC 2019



> On Apr 18, 2019, at 13:07, Jim Reid <jim at rfc1035.com> wrote:
> 
> 
> 
>> On 18 Apr 2019, at 10:46, Stephane Bortzmeyer <bortzmeyer at nic.fr> wrote:
>> 
>> Of course, it would be better to move away from DSA, but it shouldn't
>> make a SERVFAIL, just a lack of validation
> 
> ? If DSA signatures can't be validated, SERVFAIL is the correct response.

Then why does google resolver sometimes give the answer with NSes?
Sometimes it can validate DSA signature and sometimes not?

> 
> _______________________________________________
> dns-operations mailing list
> dns-operations at lists.dns-oarc.net
> https://lists.dns-oarc.net/mailman/listinfo/dns-operations
> dns-operations mailing list
> https://lists.dns-oarc.net/mailman/listinfo/dns-operations

--
Best regards

Taras Heichenko
tasic at hostmaster.ua









More information about the dns-operations mailing list