This timeout, I'm guessing this is older/naive setups that aren't expecting
to support DNSSEC, and thought "over-securing" their setup, have managed to
break the non-existence-proof process?

-Aaron

On Mon, Apr 28, 2014 at 9:32 PM, Simon Kelley <[email protected]>wrote:

...

> Neither of authoritative nameservers for test-ipv6.com return answers to
> the DS query, they just time out. They do return answers for A and AAAA
> queries. That looks broken to me.
>
> Problems like this have been at the root of most (but not all) of the
> DNSSEC failures that have been reported.
>
_______________________________________________
Cerowrt-devel mailing list
[email protected]
https://lists.bufferbloat.net/listinfo/cerowrt-devel

Reply via email to