[dns-operations] Incorrect NSEC responses from Verisign root server instances
Peter van Dijk
peter.van.dijk at powerdns.com
Sat Feb 27 10:09:11 UTC 2021
On Sat, 2021-02-27 at 01:33 +0000, Wessels, Duane via dns-operations wrote:
> Additionally, we expect this may bring some new attention to the
>
> way in which authoritative name servers respond to queries of type
>
> NSEC. Some implementations respond with referrals, while others
>
> respond with an NSEC RR in the Answer section. Verisign will be
>
> pleased to work with the community if there are ambiguities in the
>
> relevant RFCs (e.g. 4035) that would benefit from clarification,
>
> as current behavior beyond this subset of our name servers suggests.
Earlier, inconclusive, discussion on that: https://lists.dns-oarc.net/pipermail/dns-operations/2016-July/015114.html ('DS-side NSEC query')
Kind regards,
--
Peter van Dijk
PowerDNS.COM BV - https://www.powerdns.com/
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.dns-oarc.net/pipermail/dns-operations/attachments/20210227/d1378b6d/attachment.html>
More information about the dns-operations
mailing list