In message <18f2eb0d-5bd0-4cc5-b02c-2e5ea0b8c...@fugue.com>, Ted Lemon writes: > Hm. When I look for foo.alt, what I get is NXDOMAIN, not SERVFAIL. > When I validate, I get a secure denial of existence. This is the > correct behavior. Why do you think we would get a SERVFAIL?
Because your testing is incomplete. Go add a empty zone (SOA and NS records only) for alt to your recursive server. This is what needs to be done to prevent privacy leaks. Configure another recursive server to forward its queries to this server and enable validation. Now ask for foo.alt from this second server. Mark -- Mark Andrews, ISC 1 Seymour St., Dundas Valley, NSW 2117, Australia PHONE: +61 2 9871 4742 INTERNET: ma...@isc.org _______________________________________________ DNSOP mailing list DNSOP@ietf.org https://www.ietf.org/mailman/listinfo/dnsop