On Mon, Jul 9, 2012 at 12:18 PM, Paul Wouters <[email protected]> wrote:

>
> when forwarding unbound to a bind instance with dnssec support enabled,
> but dnssec validation disabled, and when querying for a wildcard instance
> (eg foo.fedorapeople.org), bind's reply to unbound is not satisfactory to
> unbound. It seems unbound is expecting an NSEC/RRSIG over the NS record
> set in the authority section, and marks the result bogus:
>
> It is not entirely clear to me if this is a bind or unbound bug.
>
> This can be simply reproduced by running bind 9.9.1 (or 9.8.x) using:
>
>
I've experienced this as well.  A DNSSEC aware, non-validating BIND
resolver does not return NSEC(3) RRs for responses containing expanded
wildcards.  If you turn on validation, it returns NSEC RRs just fine.  Any
validating resolvers (including other BIND resolvers) using the
non-validating BIND resolver recursively cannot validate wildcard
responses.  I thought I had reported this issue to bind9-bugs many months
ago, but I can't seem to find any record of it in my email...  I also can't
find my sunglasses.

Casey
_______________________________________________
dns-operations mailing list
[email protected]
https://lists.dns-oarc.net/mailman/listinfo/dns-operations
dns-jobs mailing list
https://lists.dns-oarc.net/mailman/listinfo/dns-jobs

Reply via email to