Hello,

Please, does anyone RFC-knowledgeable knows what is the official stance on this setting? If Unbound has it on "yes", queries into zones that advertise keys signed with different algorithms always end with SERVFAIL (to prevent possible attack against the weakest algorithm), otherwise they are processed without errors.

Is the same algorithm for all keys in a zone RFC required (MUST), or just a best practice recommendation (SHOULD)?

Thank you kindly in advance for any advice on the matter.

--
Best Regards,
Daniel Ryšlink

Reply via email to