[net-dns-users] NSEC::covered() ?

Dick Franks rwfranks at acm.org
Fri Apr 13 17:41:24 UTC 2018

On 12 April 2018 at 16:36, Wessels, Duane <dwessels at verisign.com> wrote:

> I see NSEC3 as a covered() method, but nothing similar for plain old
> NSEC.  Are there any helper functions available to assist with this, i.e.
> name canonicalization and comparison?

Before we add yet more stuff, a few questions need answers:

1) Is the current NSEC3 model the right shape to support your use case?

2) What improvements, if any, need to be made to the NSEC3 model?

3) Would NSEC replacement, following a similar design pattern, meet your

4) If not, why not?

> net-dns-users mailing list
> net-dns-users at nlnetlabs.nl
> https://www.nlnetlabs.nl/mailman/listinfo/net-dns-users
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.nlnetlabs.nl/pipermail/net-dns-users/attachments/20180413/f7d9e57f/attachment.htm>

More information about the net-dns-users mailing list