The following errata report has been held for document update for RFC8906, "A Common Operational Problem in DNS Servers: Failure to Communicate".
-------------------------------------- You may review the report below and at: https://www.rfc-editor.org/errata/eid7689 -------------------------------------- Status: Held for Document Update Type: Technical Reported by: Josh Soref <jso...@gmail.com> Date Reported: 2023-10-26 Held by: Warren Kumari (Ops AD) (IESG) Section: 8.2.8 Original Text ------------- expect: DO=1 to be present if an RRSIG is in the response Corrected Text -------------- expect: flag: do to be present if an RRSIG is in the response Notes ----- The same section has `expect: flag: aa to be present`, and when running the suggested command, no `DO=1` is shown, which makes the advice unhelpful. Sample command: ``` $ dig +nocookie +edns=0 +noad +norec +dnssec soa $zone @$server ; <<>> DiG 9.16.44-Debian <<>> +nocookie +edns +noad +norec +dnssec soa powerdns.com @2600:3c03::f03c:91ff:fe55:e54d ;; global options: +cmd ;; Got answer: ;; ->>HEADER<<- opcode: QUERY, status: REFUSED, id: 45268 ;; flags: qr; QUERY: 1, ANSWER: 0, AUTHORITY: 0, ADDITIONAL: 1 ;; OPT PSEUDOSECTION: ; EDNS: version: 0, flags: do; udp: 1232 ;; QUESTION SECTION: ;powerdns.com. IN SOA ;; Query time: 0 msec ;; SERVER: 2600:3c03::f03c:91ff:fe55:e54d#53(2600:3c03::f03c:91ff:fe55:e54d) ;; WHEN: Thu Oct 26 22:26:44 UTC 2023 ;; MSG SIZE rcvd: 41 ``` [ WK: For more info, see thread: https://mailarchive.ietf.org/arch/msg/dnsop/gA71yLWLZ8-eylYgKjNy9emP9hU/ It was also suggested that reminding readers that "@$server" in this case refers to an authoritative server, and not a recursive server - See Sec 8 ] -------------------------------------- RFC8906 (draft-ietf-dnsop-no-response-issue-23) -------------------------------------- Title : A Common Operational Problem in DNS Servers: Failure to Communicate Publication Date : September 2020 Author(s) : M. Andrews, R. Bellis Category : BEST CURRENT PRACTICE Source : Domain Name System Operations Area : Operations and Management Stream : IETF Verifying Party : IESG _______________________________________________ DNSOP mailing list DNSOP@ietf.org https://www.ietf.org/mailman/listinfo/dnsop