Re: [Editorial Errata Reported] RFC6672 (5297)
Warren Kumari <[email protected]> Fri, 23 Mar 2018 15:27:30 +0000
| Newsgroups | gmane.ietf.dnsext |
|---|---|
| Message-ID | <CAHw9_iJ1nJ2QJPQPtOPOzN7K+8Hx12Y=t0BQwcbp8KwjJc4+bA@mail.gmail.com> |
[ - RFC Editor for clutter ] This *seems* correct to me, but my brain turned into jelly much earlier in the week -- anyone disagree with the errata? W On Fri, Mar 23, 2018 at 3:24 PM, RFC Errata System <[email protected]> wrote: > The following errata report has been submitted for RFC6672, > "DNAME Redirection in the DNS". > > -------------------------------------- > You may review the report below and at: > http://www.rfc-editor.org/errata/eid5297 > > -------------------------------------- > Type: Editorial > Reported by: Pieter Lexis <[email protected]> > > Section: 5.3.4.1 > > Original Text > ------------- > ;; Header: QR AA RCODE=3(NXDOMAIN) > ;; OPT PSEUDOSECTION: > ; EDNS: version: 0, flags: do; udp: 4096 > > ;; Question > foo.bar.example.com. IN A > ;; Authority > bar.example.com. NSEC dub.example.com. A DNAME > bar.example.com. RRSIG NSEC [valid signature] > > Corrected Text > -------------- > ;; Header: QR AA RCODE=3(NXDOMAIN) > ;; OPT PSEUDOSECTION: > ; EDNS: version: 0, flags: do; udp: 4096 > > ;; Question > foo.bar.example.com. IN A > ;; Authority > bar.example.com. NSEC dub.example.com. A DNAME RRSIG NSEC > bar.example.com. RRSIG NSEC [valid signature] > > Notes > ----- > The NSEC record in the original text would in no case be valid as it denies it's own existence and the existence of the RRSIG, while the text indicates that " the validator can see that it is a BOGUS reply from an attacker that collated existing records from the DNS to create a confusing reply". This indicates that NSEC and RRSIG should be set in the NSEC bitmap > > Instructions: > ------------- > This erratum is currently posted as "Reported". If necessary, please > use "Reply All" to discuss whether it should be verified or > rejected. When a decision is reached, the verifying party > can log in to change the status and edit the report, if necessary. > > -------------------------------------- > RFC6672 (draft-ietf-dnsext-rfc2672bis-dname-26) > -------------------------------------- > Title : DNAME Redirection in the DNS > Publication Date : June 2012 > Author(s) : S. Rose, W. Wijngaards > Category : PROPOSED STANDARD > Source : DNS Extensions > Area : Internet > Stream : IETF > Verifying Party : IESG > > _______________________________________________ > dnsext mailing list > [email protected] > https://www.ietf.org/mailman/listinfo/dnsext -- I don't think the execution is relevant when it was obviously a bad idea in the first place. This is like putting rabid weasels in your pants, and later expressing regret at having chosen those particular rabid weasels and that pair of pants. ---maf _______________________________________________ dnsext mailing list [email protected] https://www.ietf.org/mailman/listinfo/dnsext