[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [DNSOP] Fw: New Version Notification for draft-bellis-dns-recursive-discovery-00



In message <1F61DD04-14A6-4349-8650-9CF27D27C3BC at hopcount.ca>, Joe Abley writes
:
> 
> On 2009-10-20, at 19:29, Mark Andrews wrote:
> 
> >> ARPA will soon be signed, so I don't think this is much to worry
> >> about.  If the powers that be finally agree to make NXDOMAIN/NODATA
> >> synthesis the default in the upcoming minor DNSSEC revision, this  
> >> will
> >> also help to cut down the number of requests.
> >
> > And LOCAL.ARPA would need to be a unsigned delegation.
> 
> Could you explain this? The draft under discussion specifies that  
> LOCAL.ARPA is not to be delegated at all, so your sentence above  
> confuses me.

For LOCAL.ARPA to be accepted you need a break in the DNSSEC trust
chain.  You can only break a trust chain at a delegation.
 
> Joe
-- 
Mark Andrews, ISC
1 Seymour St., Dundas Valley, NSW 2117, Australia
PHONE: +61 2 9871 4742                 INTERNET: marka at isc.org