Order of a record and its RRSIG in response

Sourav Sain <[email protected]> Tue, 14 Jan 2014 15:55:46 +0000
Newsgroups gmane.ietf.dnsext
Message-ID <F04702D34F7A2740A330302703120864385E0497@SINEX14MBXC421.southpacific.corp.microsoft.com>
Hi

RFC 4035, section 3.1.1, mentions when a security-aware authoritative Name Server should include RRSIG records in response while placing a signed RRSET in a section in response.

Is there any clarification on the order in which a signed record and its associated RRSIG are to be included in a section. For example when including an A record and its RRSIG, is it that the name Server will always place the A record first followed by its RRSIG in response or can it be RRSIG of A record followed by the A record as well?

Going further, if, for example, a query comes for a.example.com type ALL and there are A and AAAA records for a.example.com in the zone, is there an expected order in which the authoritative name server will include the 4 records (A, RRSIG(A), AAAA, RRSIG(AAAA)) in response's answer section? Is there any guidance around this.

Thanks,
Sourav Sain

_______________________________________________
dnsext mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/dnsext