Re: Naked domain resolution with DNSSEC

Tony Finch <[email protected]>
Newsgroups gmane.ietf.dnsext
Message-ID <[email protected]>
Kumar Ashutosh <[email protected]> wrote:
>
> Now as ROOT ( "." ) zone is signed. Root says that COM is signed by
> replying with DS record for COM. A DNSSEC aware resolver with this data
> will conclude that COM is signed. Hence a record under COM should be
> signed unless it's a delegation NS record (at the zone cut).

Records under .com can also be unsigned if they are under a provably
insecure delegation.

> COM replies with NS record pointing to NS1 without any RRSIG and NSEC3
> (as DS for myzone.com is absent indicating an insecure delegation),
> which is expected.

No: if myzone.com is unsigned the referral will include a proof of
insecurity, like this:

; <<>> DiG 9.9.4rc1 <<>> +dnssec +norec myzone.com in a @a.gtld-servers.net
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 42648
;; flags: qr; QUERY: 1, ANSWER: 0, AUTHORITY: 6, ADDITIONAL: 3

;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags: do; udp: 4096
;; QUESTION SECTION:
;myzone.com.            IN A

;; AUTHORITY SECTION:
myzone.com.             2d IN NS ns1.myzone.com.
myzone.com.             2d IN NS ns2.myzone.com.
CK0POJMG874LJREF7EFN8430QVIT8BSM.com. 1d IN NSEC3 1 1 0 - (
                                CK0RFQAOES8CTVNVNH4G6Q85NOQAQ8I9
                                NS SOA RRSIG DNSKEY NSEC3PARAM )
CK0POJMG874LJREF7EFN8430QVIT8BSM.com. 1d IN RRSIG NSEC3 8 2 86400 (
                                20131009044051 20131002033051 8795 com.
                                JCPiPpefxwjdDLZFWX2Wab+EthcL8zhDJdT7hykL1w0v
                                8PlkE0wqQiCJMp1DG0AZITP9sk9YcNyhCK3cZz6SAjl7
                                DtR/yhqi9zY9Ra/bESrmrLHI7Iw8boG7Us9UPebdMU4o
                                vhe4nNLqwnf6GGJw3lSAzzFpr5UDeIVmS5EdDzs= )
KQ2VMKJAFRRU1S029E7TDJ2ARQAE2DEQ.com. 1d IN NSEC3 1 1 0 - (
                                KQ33P6J6S3E7AUT6M20OD79E277MR85S
                                NS DS RRSIG )
KQ2VMKJAFRRU1S029E7TDJ2ARQAE2DEQ.com. 1d IN RRSIG NSEC3 8 2 86400 (
                                20131008044035 20131001033035 8795 com.
                                jYuq/3PGoVYECWWDT6ZrxBPEbQjEjQa5CmRa1s7mJDz4
                                ULJBCA5gubj3nRTmx93mf/1DoHZoq/5ZIwl9SvzQXCKl
                                Q79NsVRXWuZOU5CuvNefNsf/RVL5nMjp5rLOk8MvaYNR
                                duZj8hJaHz3cP4nLwg0wv7JmjAO0WCiBSLwiF9s= )

;; ADDITIONAL SECTION:
ns1.myzone.com.         2d IN A 204.244.181.149
ns2.myzone.com.         2d IN A 204.244.181.150

;; Query time: 146 msec
;; SERVER: 2001:503:a83e::2:30#53(2001:503:a83e::2:30)
;; WHEN: Thu Oct 03 17:27:34 BST 2013
;; MSG SIZE  rcvd: 592

Tony.
-- 
f.anthony.n.finch  <[email protected]>  http://dotat.at/
Forties, Cromarty: East, veering southeast, 4 or 5, occasionally 6 at first.
Rough, becoming slight or moderate. Showers, rain at first. Moderate or good,
occasionally poor at first.
_______________________________________________
dnsext mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/dnsext
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.