Re: DNSSEC DS Record

2017-07-14 Thread Evan Hunt
On Fri, Jul 14, 2017 at 05:11:18PM -0500, /dev/rob0 wrote: > > Does zbc.com (for example) need DS, or is just passed by the TLD? > > Zbc.com. is not a zone, it is a CNAME in the com. TLD. There would > be no NS to delegate to, therefore no DS. Actually it *is* a zone: the .com TLD delegates to

Re: DNSSEC DS Record

2017-07-14 Thread /dev/rob0
On Fri, Jul 14, 2017 at 04:41:07PM -0400, sami's strat wrote: > What about the child zone? Do I need a DS record for the child No, not in the delegated zone. > zone as well? I see a good number of big DNS players in DNS (no > names) that do have DS records in there zones. Nothing will use it

Re: DNSSEC DS Record

2017-07-14 Thread sami's strat
What about the child zone? Do I need a DS record for the child zone as well? I see a good number of big DNS players in DNS (no names) that do have DS records in there zones. Does zbc.com (for example) need DS, or is just passed by the TLD? TIA On Fri, Jul 14, 2017 at 5:20 AM, Steven Carr wro

Re: delegation NS records

2017-07-14 Thread Jacob via bind-users
RFC2182 at least 3, recommends 5 - 7 Thank You, Jacob D. Evans [ http://twitter.jacobdevans.com/ ] [ http://facebook.jacobdevans.com/ ] [ http://www.jacobdevans.com/ ] [ http://linkedin.jacobdevans.com/ ] [ mailto:sig-cont...@jacobdevans.com ] [ http://serverfault.com/users/200560/jacob-ev

Re: delegation NS records

2017-07-14 Thread Niall O'Reilly
On 14 Jul 2017, at 14:07, b...@zq3q.org wrote: > only a single **delegation** NS record > needed Actually, there should be two or more, and their IP addresses should belong to different networks. RFC1034, section 4.1: A given zone will be available from several name servers to insure its av

Re: delegation NS records

2017-07-14 Thread bind
Yesterday, Niall corrected me off list. Hopefully what I write below is now correct: Assume our nameserver SOA and related authoritatve NS record are in the zone w/$ORIGIN" "example.com.". Regardless of what the FQDN for the nameserver itself is, only a single **delegation** NS recor

Re: DNSSEC DS Record

2017-07-14 Thread Steven Carr
On 14 July 2017 at 01:52, sami's strat wrote: > However, the zone is missing the DS record, completely. That being said, > what is the offset, or result? I don't see an AD flag when querying the > zone. Other then that, are there any other ramifications? Without the DS record in the parent the

Re: delegation NS records

2017-07-14 Thread Matus UHLAR - fantomas
On 13.07.17 19:39, b...@zq3q.org wrote: Interesting. I think the glue record make sense. I'm not planning to do this. :-> I do not see any delegation NS record for otherdomain.com above. Is this right?: TLD com zone: example.comIN NS ns.otherdomain.com ns.example.com IN A