[Dnssec-trigger] A new kind of broken hotspot: RRSIG are OK but NSEC3 are deleted

Paul Wouters paul at xelerance.com
Thu Oct 27 17:53:01 UTC 2011


On Thu, 27 Oct 2011, Stephane Bortzmeyer wrote:

> May be dnssec-trigger should test NSEC/NSEC3 on non-existent records
> as well?
>
> Signed names are OK since there is no NSEC to send back.

unless they are synthesized from a wildcard.......

Paul



More information about the dnssec-trigger mailing list