On Mon, May 09, 2011 at 01:41:08PM +0200,
 Marc Lampo <marc.la...@eurid.eu> wrote 
 a message of 28 lines which said:

> So the "error" of the mismatched must be in the SHA-2 DS records ?

Yes.

> And *not* in the SHA-1's ?  Or in both ?

RFC 4509 section 3 gives a strong priority to SHA-2. So, there is no
symmetry: the problem exists only if the invalid DS is the one hashed
with SHA-2.
_______________________________________________
bind-users mailing list
bind-users@lists.isc.org
https://lists.isc.org/mailman/listinfo/bind-users

Reply via email to