> On Mon, Sep 01, 2008 at 04:49:12PM -0400,
>  Paul Wouters <[EMAIL PROTECTED]> wrote 
>  a message of 18 lines which said:
> 
> > many issues there which are not addressed [...] authenticated denial
> > of existence,
> 
> Although I agree with your criticism that there is no published
> *specification* of DNScurve (wether in Internet-Draft form or else),
> this specific issue seems addressed today: DNScurve signs the packet,
> not the resource records, and therefore a NXDOMAIN response can be
> signed (unlike what happens with DNSSEC).

        A NXDOMAIN response if cyptographically proved with DNSSEC.

        There are other rcodes that DNSSEC does not cover but NXDOMAIN
        is not one of them.

        Mark
-- 
Mark Andrews, ISC
1 Seymour St., Dundas Valley, NSW 2117, Australia
PHONE: +61 2 9871 4742                 INTERNET: [EMAIL PROTECTED]
_______________________________________________
DNSOP mailing list
DNSOP@ietf.org
https://www.ietf.org/mailman/listinfo/dnsop

Reply via email to