Re: Authenticated denial of existence...
Miek Gieben <[email protected]> Wed, 20 Nov 2013 21:37:40 +0000
| Newsgroups | gmane.ietf.dnsext |
|---|---|
| Message-ID | <[email protected]> |
[ Quoting <[email protected]> in "Re: [dnsext] Authenticated denial o..." ] > > You may want to have some discussion about the pointlessness of > NSEC3 in highly structured zones like ip6.arpa and in-addr.arpa. > These can be walked even with NSEC3 due to their structure. > > You may want to point out that a NSEC proves the existance of all > empty non-terminals between the two names in it hence contains the > closest provable encloser. Ack and ack. These would indeed be good things to add. > There is a bias that NSEC3 is better than NSEC. They are just > different. NSEC3 is actually worse for the typical trivial zone > as it doesn't help with zone walking as you can guess the names and > adds pointless computational load on both authoritative servers and > validators. I agree with your assertions, but I hope to keep the draft purely technical. Grtz, Miek _______________________________________________ dnsext mailing list [email protected] https://www.ietf.org/mailman/listinfo/dnsext