On Fri, 05 Feb 2010 08:18:35 +1100, Mark Andrews <[email protected]> said:
> In message <[email protected]>, Alexander Gall > writes: >> >> All of those are NSEC3-agnostic. They should not do any DNSSEC >> processing for the ch zone, because they don't support algorithm #7. > Yes and no. Just because you are using a algorithm that is unsupported > doesn't mean that you won't get queries looking for the break point > between supported and unsupported algorithms. DS queries are used > to find that break point. But isn't the break point at the DLV/trusted-key level for ch? -- Alex _______________________________________________ bind-users mailing list [email protected] https://lists.isc.org/mailman/listinfo/bind-users

