On Mar 30, 2017, at 1:11 PM, Steve Crocker <[email protected]> wrote:
> And I remain puzzled as to why a simple NXDOMAIN response from the root isn’t 
> exactly the right thing and why it matters whether it’s signed or not.

Because DNSSEC.   A validating stub will see a proof of nonexistence and ignore 
anything the local recursive resolver offers.
_______________________________________________
DNSOP mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/dnsop

Reply via email to