Re: [dns-operations] chrome's 10 character QNAMEs to detect NXDOMAIN rewriting

2013-11-28 Thread Robert Edmonds
Mark Andrews wrote: > In message <20131128000148.ga20...@mycre.ws>, Robert Edmonds writes: > > i'm curious as to exactly what this root zone slaved resolver > > configuration looks like and how it would behave. i don't believe i've > > ever set up a resolver like that before. > > zone "." IN {

Re: [dns-operations] algorithm rollover strategies

2013-11-28 Thread Peter Koch
On Thu, Nov 28, 2013 at 10:16:33AM +0100, Matthijs Mekking wrote: > http://tools.ietf.org/html/rfc6840#section-5.11 I will consult the "Updated by" clause in the RFC index. I will consult the "Updated by" clause in the RFC index. I will consult ... > to make sure that your zone does not go

Re: [dns-operations] algorithm rollover strategies

2013-11-28 Thread Matthijs Mekking
On 11/27/2013 10:24 PM, Peter Koch wrote: > On Wed, Nov 27, 2013 at 08:48:05AM -0500, Edward Lewis wrote: > >> It should be: >> >> There MUST be an RRSIG for each RRset using at least one DNSKEY of >> each algorithm in the zone apex DNSKEY RRset that is also in the DS RRset. >> The apex DNSKEY R