Re: [Technical Errata Reported] RFC4592 (5119)
Mark Andrews <[email protected]> Fri, 22 Sep 2017 13:56:00 +1000
| Newsgroups | gmane.ietf.dnsext |
|---|---|
| Message-ID | <[email protected]> |
Such NSEC records are identifiable as part of the validation processs and can be flagged to be ignored as part of the synthesis process and/or be stored with the original wildcard name. As a aside named saves validated wild card answers with their original wildcard name so they can be found for data synthesis purposes. I agree with Ed Lewis that this is not a problem with this RFC4592. Mark In message <[email protected]>, RFC Errata System writes : > The following errata report has been submitted for RFC4592, > "The Role of Wildcards in the Domain Name System". > > -------------------------------------- > You may review the report below and at: > http://www.rfc-editor.org/errata/eid5119 > > -------------------------------------- > Type: Technical > Reported by: Karst Koymans <[email protected]> > > Section: 4.7 > > Original Text > ------------- > 4.7. NSEC RRSet at a Wildcard Domain Name > > Wildcard domain names in DNSSEC signed zones will have an NSEC RRSet. > Synthesis of these records will only occur when the query exactly > matches the record. Synthesized NSEC RRs will not be harmful as they > will never be used in negative caching or to generate a negative > response [RFC2308]. > > > Corrected Text > -------------- > 4.7. NSEC RRSet at a Wildcard Domain Name > > Wildcard domain names in DNSSEC signed zones will have an NSEC RRSet. > NSEC RRSets must not be synthesized from this wildcard NSEC. > > Notes > ----- > Synthesizing these records would destroy the semantics of the NSEC chain and c > ould be very harmful if implementations would cache them and use them for "Agg > ressive Use of DNSSEC-Validated Cache" (RFC 8198). > > Instructions: > ------------- > This erratum is currently posted as "Reported". If necessary, please > use "Reply All" to discuss whether it should be verified or > rejected. When a decision is reached, the verifying party > can log in to change the status and edit the report, if necessary. > > -------------------------------------- > RFC4592 (draft-ietf-dnsext-wcard-clarify-11) > -------------------------------------- > Title : The Role of Wildcards in the Domain Name System > Publication Date : July 2006 > Author(s) : E. Lewis > Category : PROPOSED STANDARD > Source : DNS Extensions > Area : Internet > Stream : IETF > Verifying Party : IESG > > _______________________________________________ > dnsext mailing list > [email protected] > https://www.ietf.org/mailman/listinfo/dnsext -- Mark Andrews, ISC 1 Seymour St., Dundas Valley, NSW 2117, Australia PHONE: +61 2 9871 4742 INTERNET: [email protected] _______________________________________________ dnsext mailing list [email protected] https://www.ietf.org/mailman/listinfo/dnsext