On Wed, Sep 02, 2015 at 08:28:10AM +1000,
 Mark Andrews <ma...@isc.org> wrote 
 a message of 49 lines which said:

> This is recursive resolver to root server privacy which is off charter
> for DPRIVE.
> 
> Now there are two ways to solve this as the root is signed.
> 
> 1. Recommend *every* recursive server holds a copy of the root zone.

The problem is more general than that. It is not only the root (well,
the sniffers along the path to the root name servers), it is a
recursive-to-authoritative problem. Your solution does not work for
.com or even .fr.

_______________________________________________
DNSOP mailing list
DNSOP@ietf.org
https://www.ietf.org/mailman/listinfo/dnsop

Reply via email to