Re: Naked domain resolution with DNSSEC
Dave Lawrence <[email protected]>
| Newsgroups | gmane.ietf.dnsext |
|---|---|
| Message-ID | <[email protected]> |
Kumar Ashutosh writes: > The resolver was expecting a signed response for everything under > COM, gets an unsigned response and marks them as BOGUS and returns a > SERV_FAIL Some resolvers, do let the response pass but with AD bit > set to 0 which a DNSSEC aware end client may not accept. You've observed these behaviours? With which nameservers? _______________________________________________ dnsext mailing list [email protected] https://www.ietf.org/mailman/listinfo/dnsext