On Thu, Jan 11, 2018 at 11:26 AM, 神明達哉 <[email protected]> wrote:
> At Wed, 10 Jan 2018 17:05:00 -0800, > Ólafur Guðmundsson <[email protected]> wrote: > > > > That is, it answers as if it is authoritative and the DS record does > > > not exist. DS-aware recursive nameservers will query the parent > zone > > > at delegation points, so will not be affected by this. > > > > > I hate having my own RFC thrown at me, > > but it may or may not apply as there is another corner case that I/WG did > > not consider, > > what if the NameServer is authoritative for a zone above the parent. > > In this case it has to select does it answer from the closest zone that > can > > answer DS record or > > from the zone it self. > > > > In the spirit of being helpful to recursive resolvers the right answer > IMHO > > is the referral from the > > zone above the query name. > > I'm not sure if I understand you so please let me be more explicit. > Are you talking about the so-called grandparent problem case, like the > case of this thread? > yes
_______________________________________________ DNSOP mailing list [email protected] https://www.ietf.org/mailman/listinfo/dnsop
