In message <18f2eb0d-5bd0-4cc5-b02c-2e5ea0b8c...@fugue.com>, Ted Lemon writes:
> Hm.   When I look for foo.alt, what I get is NXDOMAIN, not SERVFAIL.
> When I validate, I get a secure denial of existence.   This is the
> correct behavior.   Why do you think we would get a SERVFAIL?

Because your testing is incomplete.

Go add a empty zone (SOA and NS records only) for alt to your
recursive server.  This is what needs to be done to prevent
privacy leaks.

Configure another recursive server to forward its queries to this
server and enable validation.

Now ask for foo.alt from this second server.

Mark
-- 
Mark Andrews, ISC
1 Seymour St., Dundas Valley, NSW 2117, Australia
PHONE: +61 2 9871 4742                 INTERNET: ma...@isc.org

_______________________________________________
DNSOP mailing list
DNSOP@ietf.org
https://www.ietf.org/mailman/listinfo/dnsop

Reply via email to