Re: nsec3 hash collision
Fredrik Pettai <[email protected]>
| Newsgroups | gmane.network.dns.nsd.general |
|---|---|
| Message-ID | <[email protected]> |
> On 6 Feb 2017, at 09:40, W.C.A. Wijngaards <[email protected]> wrote: > > Hi Fredrik, > > Change the nsec3 salt at the zone signer for this zone. The master is a InfoBlox appliance I've heard. > The sender is sending queries for a nonexist name that hashes (exactly) > to the same hash as the hash for an existing name in the zone. Oh, is this possible? This is just a small zone containing ~1200 RRs (Which leads to the question if it exist any kind of statistics regarding this?) Looks more like a bug or non-existing or bad verification at the master/signer side > This is what NSD logs. With this printout you can figure out that the short > NSEC3-string for the query name, and the nsec3 string for one of the > names in your zone, have the same hash. > > NSD has replied SERVFAIL to that client, since an NSEC3 nonexistance > proof is impossible. So, no issues except the log file spam. > > At what verbosity level should I log these messages, you would think? > Then I'll fix the code for that. I’m running at verbosity: 2 I have no special requirements regarding the verbosity level. Would it be wrongly placed if it was moved to verbosity 3? Perhaps just one notification about hash collision would suffice for verbosity 2? Re, /P _______________________________________________ nsd-users mailing list [email protected] https://open.nlnetlabs.nl/mailman/listinfo/nsd-users
signature.asc
(application/pgp-signature, 496 B)
-----BEGIN PGP SIGNATURE----- Comment: GPGTools - https://gpgtools.org iQEcBAEBCgAGBQJYmD1bAAoJEMiUPhq0toFZO94H/Aosd6FS/2D+xjk0+skog060 O4a0pGefgx8sPENTtrsvYa+ToAPoJR1teWjWcmeenG/tnfS1xumn6H7L9F+yXo+o +lbUxWXWhUUU1Q7YeASVTzBwAAL4qBayIGFWJOzXzp6dgwvTPDm4XW5i9zGQSObE 5rQBGgEhszeZHqLGSvHDJ6weZgIhJe/R83uB4v+GbtwrcXWnbV4B1epll6lYEOya IKuDhCJlFK/JPsBFU4KhFORtvcLYCmM4a23cWqKfmX81D+9WJ5EM5bVQa9hM18Mn t3fXnZ4SGJOpFY5jFJo5KyjY3Cz7ZzOvTik/PnROz4EjkBmHrWS8NXqDOD+Uqtg= =hWhP -----END PGP SIGNATURE-----