Order of a record and its RRSIG in response
Sourav Sain <[email protected]> Tue, 14 Jan 2014 15:55:46 +0000
| Newsgroups | gmane.ietf.dnsext |
|---|---|
| Message-ID | <F04702D34F7A2740A330302703120864385E0497@SINEX14MBXC421.southpacific.corp.microsoft.com> |
Hi RFC 4035, section 3.1.1, mentions when a security-aware authoritative Name Server should include RRSIG records in response while placing a signed RRSET in a section in response. Is there any clarification on the order in which a signed record and its associated RRSIG are to be included in a section. For example when including an A record and its RRSIG, is it that the name Server will always place the A record first followed by its RRSIG in response or can it be RRSIG of A record followed by the A record as well? Going further, if, for example, a query comes for a.example.com type ALL and there are A and AAAA records for a.example.com in the zone, is there an expected order in which the authoritative name server will include the 4 records (A, RRSIG(A), AAAA, RRSIG(AAAA)) in response's answer section? Is there any guidance around this. Thanks, Sourav Sain _______________________________________________ dnsext mailing list [email protected] https://www.ietf.org/mailman/listinfo/dnsext