Re: Naked domain resolution with DNSSEC
Jim Reid <[email protected]>
| Newsgroups | gmane.ietf.dnsext |
|---|---|
| Message-ID | <[email protected]> |
On 6 Oct 2013, at 17:16, Sourav Sain <[email protected]> wrote: > Our concern is, a security aware validating server, having root or COM's Trust Anchor, will expect an RRSIG in the response for facebook.com, type=A, not having which, will conclude the response as BOGUS. Your concern would be valid if that was how DNSSEC works. But it doesn't. facebook.com is not signed. The zone has no DNSKEYs or RRSIGs. There are no DS records in .com for facebook.com either: hardly surprising because facebook.com is not signed and has no key-signing keys. A validating resolver would not expect to find an RRSIG for facebook.com's A record RRset. It would not be able to validate that RRSIG if it was present because the zone does not have signed delegation. [Well, not unless it had some other out of band TA for facebook.com.] It would know from the metadata in the .com zone that facebook.com was not signed and continue to resolve names in that domain, albeit without doing any validation. The answers that validating resolver returned to its clients will have the AD (Authentic Data) bit set in the DNS header to indicate if the answer had been sucessfully validated or not validated at all. _______________________________________________ dnsext mailing list [email protected] https://www.ietf.org/mailman/listinfo/dnsext