RFC 5155 has a contradiction when dealing with empty non-terminals: It always requires sending a NSEC3 when QTYPE is not DS, but in some scenarios it is not required to add a NSEC3 record when signing. One such scenario is an empty non-terminal derived from an unsigned delegation.
Errata 3441 resolves that by fixing the name server and validator. We do not have to do anything. But since fixing interoperability between errata3441-compatible servers and errata3441-incompatible is easily achieved by adding a NSEC3 record, I argue we should always put NSEC3 records on empty non-terminals.
- is cloned by
-
OPENDNSSEC-550 CLONE - Deal with errata 3441 of RFC 5155
-
- Closed
-