I can't find a draft to cite for this talk, so this refers to the slides

"DNSSEC Protocol Modifications"
(http://www.rfc-editor.org/rfc/rfc4035.txt) has an explicit prohibition on
names owning only NSEC and RRSIG.


I'm not holding this up as a royal edict.  But it's there in plain text.

Fortunately there's a rationale why the requirement language is there, so
there's a starting point to "work on this."

"2.3.  Including NSEC RRs in a Zone


   An NSEC record (and its associated RRSIG RRset) MUST NOT be the only
   RRset at any particular owner name."

Attachment: smime.p7s
Description: S/MIME cryptographic signature

DNSOP mailing list

Reply via email to