[dns-operations] Incorrect NSEC responses from Verisign root server instances

Peter van Dijk peter.van.dijk at powerdns.com
Sat Feb 27 10:09:11 UTC 2021


On Sat, 2021-02-27 at 01:33 +0000, Wessels, Duane via dns-operations wrote:
> Additionally, we expect this may bring some new attention to the
> 
> way in which authoritative name servers respond to queries of type
> 
> NSEC.  Some implementations respond with referrals, while others
> 
> respond with an NSEC RR in the Answer section.  Verisign will be
> 
> pleased to work with the community if there are ambiguities in the
> 
> relevant RFCs (e.g. 4035) that would benefit from clarification,
> 
> as current behavior beyond this subset of our name servers suggests.

Earlier, inconclusive, discussion on that: https://lists.dns-oarc.net/pipermail/dns-operations/2016-July/015114.html ('DS-side NSEC query')

Kind regards,
-- 
Peter van Dijk
PowerDNS.COM BV - https://www.powerdns.com/
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.dns-oarc.net/pipermail/dns-operations/attachments/20210227/d1378b6d/attachment.html>


More information about the dns-operations mailing list