[dns-operations] Possibly-incorrect NSEC responses from many RSOs

Vladimír Čunát vladimir.cunat+ietf at nic.cz
Tue Mar 2 14:02:29 UTC 2021


On 3/2/21 2:23 PM, Peter van Dijk wrote:
> My suggestion (seriously): prohibit NSEC and RRSIG queries. They are
> ambiguous and nobody has any use for their output anyway. Not
> supporting them can really simplify some implementations as well (I
> submit RFC 8482 as exhibit A.)

+1  In the sense that I can't see why a meaningful answer should be 
*required* in those cases.  I don't really mind if someone does such a 
query or tries to provide a meaningful answer to it.

--Vladimir | knot-resolver.cz





More information about the dns-operations mailing list