Re: Authenticated denial of existence...

Miek Gieben <[email protected]> Wed, 20 Nov 2013 21:37:40 +0000
Newsgroups gmane.ietf.dnsext
Message-ID <[email protected]>
[ Quoting <[email protected]> in "Re: [dnsext] Authenticated denial o..." ]
> 
> You may want to have some discussion about the pointlessness of
> NSEC3 in highly structured zones like ip6.arpa and in-addr.arpa.
> These can be walked even with NSEC3 due to their structure.
> 
> You may want to point out that a NSEC proves the existance of all
> empty non-terminals between the two names in it hence contains the
> closest provable encloser.

Ack and ack. These would indeed be good things to add.

> There is a bias that NSEC3 is better than NSEC.  They are just
> different.  NSEC3 is actually worse for the typical trivial zone
> as it doesn't help with zone walking as you can guess the names and
> adds pointless computational load on both authoritative servers and
> validators.

I agree with your assertions, but I hope to keep the draft purely
technical.

Grtz, Miek
_______________________________________________
dnsext mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/dnsext