Re: nsec3 hash collision

Fredrik Pettai <[email protected]>
Newsgroups gmane.network.dns.nsd.general
Message-ID <[email protected]>
> On 6 Feb 2017, at 09:40, W.C.A. Wijngaards <[email protected]> wrote:
> 
> Hi Fredrik,
> 
> Change the nsec3 salt at the zone signer for this zone.

The master is a InfoBlox appliance I've heard.

> The sender is sending queries for a nonexist name that hashes (exactly)
> to the same hash as the hash for an existing name in the zone.

Oh, is this possible? This is just a small zone containing ~1200 RRs
(Which leads to the question if it exist any kind of statistics regarding this?)
Looks more like a bug or non-existing or bad verification at the master/signer side

>  This is what NSD logs.  With this printout you can figure out that the short
> NSEC3-string for the query name, and the nsec3 string for one of the
> names in your zone, have the same hash.
> 
> NSD has replied SERVFAIL to that client, since an NSEC3 nonexistance
> proof is impossible.  So, no issues except the log file spam.
> 
> At what verbosity level should I log these messages, you would think?
> Then I'll fix the code for that.

I’m running at verbosity: 2
I have no special requirements regarding the verbosity level.

Would it be wrongly placed if it was moved to verbosity 3?
Perhaps just one notification about hash collision would suffice for verbosity 2?

Re,
/P

_______________________________________________
nsd-users mailing list
[email protected]
https://open.nlnetlabs.nl/mailman/listinfo/nsd-users
signature.asc (application/pgp-signature, 496 B)
-----BEGIN PGP SIGNATURE-----
Comment: GPGTools - https://gpgtools.org

iQEcBAEBCgAGBQJYmD1bAAoJEMiUPhq0toFZO94H/Aosd6FS/2D+xjk0+skog060
O4a0pGefgx8sPENTtrsvYa+ToAPoJR1teWjWcmeenG/tnfS1xumn6H7L9F+yXo+o
+lbUxWXWhUUU1Q7YeASVTzBwAAL4qBayIGFWJOzXzp6dgwvTPDm4XW5i9zGQSObE
5rQBGgEhszeZHqLGSvHDJ6weZgIhJe/R83uB4v+GbtwrcXWnbV4B1epll6lYEOya
IKuDhCJlFK/JPsBFU4KhFORtvcLYCmM4a23cWqKfmX81D+9WJ5EM5bVQa9hM18Mn
t3fXnZ4SGJOpFY5jFJo5KyjY3Cz7ZzOvTik/PnROz4EjkBmHrWS8NXqDOD+Uqtg=
=hWhP
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.