Re: [Technical Errata Reported] RFC5155 (4993)
Alex Bligh <[email protected]> Wed, 19 Apr 2017 07:16:51 +0200
| Newsgroups | gmane.ietf.dnsext |
|---|---|
| Message-ID | <[email protected]> |
> On 13 Apr 2017, at 18:12, RFC Errata System <[email protected]> wrote: > > The zone prior to NSEC3 signing seems to have contained an unexpected > 2t7b4g4vsa5smi47k61mv5bv1a22bojr.example. A 192.0.2.127 > which was then lovingly included in the NSEC3 chain. > > The error is readily detectable from the list of hashes of the original owner names. The source zone prior to signing can never contain a hashed name. > The inclusion may or may not be an error, but that statement is incorrect. The source zone *can* include labels that happen to be the result of a later hashing (by coincidence) and there was much discussion at the time as to whether this would cause issues (it doesn't). Of course it's not likely in practice, but it is possible. It seems to me that whether this is in fact an error depends on whether the possibility of this is being deliberately illustrated or not; if it is, then perhaps it might be better to call this out directly. -- Alex Bligh _______________________________________________ dnsext mailing list [email protected] https://www.ietf.org/mailman/listinfo/dnsext