[dns-operations] sophosxl.net problem?

Viktor Dukhovni ietf-dane at dukhovni.org
Tue Nov 12 23:26:00 UTC 2019


> On Nov 12, 2019, at 2:32 PM, Paul Vixie <paul at redbarn.org> wrote:
> 
> In context, the leak I was talking about was the use of recursive data
> in authoritative answers, coming from servers configured for both.

Can you be more explicit about what you mean by "in authoritative
answers"?  Do you mean answers to queries with "RD=0", or answers
with "AA=1"?

It seems that a dual-mode BIND9 server does return recursive data
in answer to queries with "RD=0", but such answers then also have
"AA=0".

-- 
	Viktor.




More information about the dns-operations mailing list