> On Mon, Sep 01, 2008 at 04:49:12PM -0400, > Paul Wouters <[EMAIL PROTECTED]> wrote > a message of 18 lines which said: > > > many issues there which are not addressed [...] authenticated denial > > of existence, > > Although I agree with your criticism that there is no published > *specification* of DNScurve (wether in Internet-Draft form or else), > this specific issue seems addressed today: DNScurve signs the packet, > not the resource records, and therefore a NXDOMAIN response can be > signed (unlike what happens with DNSSEC).
A NXDOMAIN response if cyptographically proved with DNSSEC. There are other rcodes that DNSSEC does not cover but NXDOMAIN is not one of them. Mark -- Mark Andrews, ISC 1 Seymour St., Dundas Valley, NSW 2117, Australia PHONE: +61 2 9871 4742 INTERNET: [EMAIL PROTECTED] _______________________________________________ DNSOP mailing list DNSOP@ietf.org https://www.ietf.org/mailman/listinfo/dnsop