Re: Authenticated denial of existence...

"Jiankang Yao" <[email protected]> Wed, 20 Nov 2013 14:59:40 +0800
Newsgroups gmane.ietf.dnsext
Message-ID <[email protected]>
good writing of this draft.

I am interested the following text in section 3:
"   2.  The DNS packet header is not signed.  This means that a "status:
       NXDOMAIN" can not be trusted.  In fact the entire header may be
       forged, including the AD bit (AD stands for Authentic Data, see
       RFC 3655 [RFC3655]), which may give some food for thought;
"
so if the resolver is attacked, such as hacking the "status" field or the whole header, what will happen?





Jiankang Yao

From: Ted Lemon
Date: 2013-11-20 11:30
To: Group 
Subject: [dnsext] Authenticated denial of existence...
Is this on anyone's radar?   What are your thoughts about it?

https://datatracker.ietf.org/doc/draft-gieben-auth-denial-of-existence-dns/

_______________________________________________
dnsext mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/dnsext

_______________________________________________
dnsext mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/dnsext