Re: Naked domain resolution with DNSSEC
Jim Reid <[email protected]> Wed, 23 Oct 2013 19:05:27 +0100
| Newsgroups | gmane.ietf.dnsext |
|---|---|
| Message-ID | <[email protected]> |
On 23 Oct 2013, at 18:39, Kumar Ashutosh <[email protected]> wrote: > The Microsoft authoritative DNS servers prevent adding CNAMEs at the zone apex. But there may be other DNS servers which may be allowing this and the validating resolvers are returning Serv_fail, As Andrew suggested. This is how it should be. If a name exists as a CNAME, it cannot exist as any other RRtype. Except of course for any RRSIGs and NSEC or NSEC3's if the zone is signed. Adding a CNAME at the zone apex fails because that name must at by definition already have at least a SOA and some NS records. _______________________________________________ dnsext mailing list [email protected] https://www.ietf.org/mailman/listinfo/dnsext