Re: nsec3 hash collision
Fredrik Pettai <[email protected]>
| Newsgroups | gmane.network.dns.nsd.general |
|---|---|
| Message-ID | <[email protected]> |
> On 6 Feb 2017, at 10:09, Fredrik Pettai <[email protected]> wrote: > >> The sender is sending queries for a nonexist name that hashes (exactly) >> to the same hash as the hash for an existing name in the zone. > > Oh, is this possible? This is just a small zone containing ~1200 RRs > (Which leads to the question if it exist any kind of statistics regarding this?) > Looks more like a bug or non-existing or bad verification at the master/signer side Hmm…perhaps I interpreted your explanation above Are you saying someone (else?) is querying the zone at my NSD slave, and that those queries (because there are a lot for log entries), are “expanded" to the exact same hash as an existing hash for another record in the zone? …which also sounds like it shouldn’t be possible (in theory). /P _______________________________________________ nsd-users mailing list [email protected] https://open.nlnetlabs.nl/mailman/listinfo/nsd-users
signature.asc
(application/pgp-signature, 496 B)
-----BEGIN PGP SIGNATURE----- Comment: GPGTools - https://gpgtools.org iQEcBAEBCgAGBQJYmECPAAoJEMiUPhq0toFZZJUH/1HFfY6IAwZLRq/e2KzSQq/E nfF3ERWblty38R7xWn/OlQj67hbaRz8mZSszUrD18CP8MaKszu0/ZiekSaZL/zKk fF1VzIGWvxN9AWeL9zyAPO0plkSDxwds7r6IGiUr6q3eYHvAN94EqtGlFU+xKG9a EZHgL6sM5+uGygIH7JRk7s+yw0jDu3WhhjtwEVUFzupkviVO5S2kIGBNA/P+BQZn aA5LV4WAGxE4nAtjlqnCIRANyjq/u9ZatvO86wJU75q6Of6WNRXCfT+V53FlVhCC +eHaIzTJxYC6M8UEsYfjecbGme6DDneFfXlD2qlz85DY3LyVji1D2Nm5SC+DsoA= =cis1 -----END PGP SIGNATURE-----