On Fri, Sep 05, 2014 at 03:11:49PM +0000, Viktor Dukhovni wrote:

>     $ dig +dnssec +norecur -t tlsa _25._tcp.mail2.clarion-hotels.cz 
> @ns.forpsi.net
>     ...
>     *.clarion-hotels.cz.    3600    IN      NSEC    mail.clarion-hotels.cz. A 
> RRSIG NSEC
>     *.clarion-hotels.cz.    3600    IN      RRSIG   NSEC 5 2 3600 
> 20141005113302 20140905113302 13077 clarion-hotels.cz. 
> lSf+ySQxo+sXxtuEZEIy7YghFeQnFlDd7vkZA8XO/ahgAzgxHZkAsQXk 
> RjoJVCLd3E3FgX55Pu0RA6IQVn1ynZFYp3l1P24bC93+l3vszNsnMKnD 
> qqjNIIzeYanNfkI34kdPpj5C1HhtrC1ZUhRwryphsKXX9KYFB/B4i+47 U2E=

The only slightly odd thing I see is the RRSIG above.  Instead of
binding all three labels of the wildcard, it binds only the last
two.  Is that how it should be?

Anyone have better insight?

-- 
        Viktor.

_______________________________________________
dane mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/dane

Reply via email to