<div dir="ltr"><div dir="ltr">On Mon, Sep 9, 2024 at 12:42 PM Viktor Dukhovni <<a href="mailto:ietf-dane@dukhovni.org">ietf-dane@dukhovni.org</a>> wrote:<br></div><div class="gmail_quote"><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">On Mon, Sep 09, 2024 at 10:50:14AM -0400, Shumon Huque wrote:<br>
<br>
> > Dear colleagues,<br>
> ><br>
> > NS1 will be rolling out an update for Compact Denial of Existence in<br>
> > DNSSEC (draft-ietf-dnsop-compact-denial-of-existence) which will<br>
> > change the codepoint for the NXNAME meta record.<br>
> ><br>
> > The new implementation will use 128 allocated by IANA replacing the<br>
> > private value 65283.<br>
> ><br>
> > We are currently planning to deploy the change in the following weeks.<br>
> ><br>
> <br>
> Thank you for the notice Jan.<br>
> <br>
> I want to note that Cloudflare has also (recently) moved to TYPE 128<br>
> for NXNAME.<br>
<br>
Indeed confirmed live deployment for Cloudflare, and not quite yet for NS1:<br></blockquote><div><br></div><div>[...]</div><div><br></div><div>NS1 looks completed now too:</div><div><br></div>$ dig +dnssec +noall +authority <a href="http://nxd1234.ns1.com">nxd1234.ns1.com</a> | awk '$4 == "NSEC"'<br><div><a href="http://nxd1234.ns1.com">nxd1234.ns1.com</a>. 3576 IN NSEC \<a href="http://000.nxd1234.ns1.com">000.nxd1234.ns1.com</a>. RRSIG NSEC TYPE128</div><div><br></div><div>Shumon.</div><div><br></div></div></div>