* Mark Andrews:

> In message <87y50auqqf....@mid.deneb.enyo.de>, Florian Weimer writes:
>> * Mark Andrews:
>> 
>> >>>    Another note is that the answer to the NS query, unlike the referral
>> >>>    sent when the question is a full qname, is in the Answer section, not
>> >>>    in the Authoritative section.  It has probably no practical
>> >>>    consequences.
>> >> 
>> >> Most resolvers do not make NS queries, and some authoritative servers
>> >> do not return useful data (or any data at all).  So using NS queries
>> >> for zone cut discovery does not work reliably.
>> >
>> > Any resolver that is DNSSEC aware will make NS queries (whether
>> > validating or not).
>> 
>> Really?  Where is this mentioned in the protocol RFCs?
>
> RFC 3658
> 2.2.1.2.  Special processing when child and an ancestor share
>           nameserver

I think this section is about DS queries, not NS queries.

_______________________________________________
DNSOP mailing list
DNSOP@ietf.org
https://www.ietf.org/mailman/listinfo/dnsop

Reply via email to