Re: CloudFlare NSEC black lies - any plans for support?
"Peter van Dijk" <[email protected]> Thu, 21 Jul 2016 14:08:16 +0200
| Newsgroups | gmane.network.dns.powerdns.devel |
|---|---|
| Message-ID | <[email protected]> |
Hello, On 21 Jul 2016, at 13:20, bert hubert wrote: > On Thu, Jul 21, 2016 at 02:00:36PM +0300, Cristian Seres wrote: >> I know about the NSEC3 narrow mode in PowerDNS. I suppose that's the best >> available option to decrease information leak at the moment. RFC7129 >> appendix B calls them "NSEC3 White Lies" which is more commonly used term >> than narrow mode, I think. > > We used it way before RFC7129, which may explain. In fact the output in 7129 was verified against PowerDNS’ narrow mode :) Kind regards, -- Peter van Dijk PowerDNS.COM BV - https://www.powerdns.com/ _______________________________________________ Pdns-dev mailing list [email protected] https://mailman.powerdns.com/mailman/listinfo/pdns-dev