Re: BIND 9.18.2 break-dnssec question

2022-05-01 Thread Mark Andrews
> On 2 May 2022, at 12:28, J Doe wrote: > > On 2022-04-29 01:18, Mark Andrews wrote: > >> break-dnssec is about if the client could detect the re-write or not using >> DNSSEC. If the client has DO=1 in the request and the normal response is >> signed then rewrites can be detected. If

Re: BIND 9.18.2 break-dnssec question

2022-05-01 Thread J Doe
On 2022-04-29 01:18, Mark Andrews wrote: break-dnssec is about if the client could detect the re-write or not using DNSSEC. If the client has DO=1 in the request and the normal response is signed then rewrites can be detected. If break-dnssec is ’no’ the rewrite will be prevented. If

Re: BIND 9.18.2 break-dnssec question

2022-04-28 Thread Mark Andrews
break-dnssec is about if the client could detect the re-write or not using DNSSEC. If the client has DO=1 in the request and the normal response is signed then rewrites can be detected. If break-dnssec is ’no’ the rewrite will be prevented. If break-dnssec is ‘yes’ then the rewrite will

BIND 9.18.2 break-dnssec question

2022-04-28 Thread J Doe
Hi, I am configuring an RPZ for a validating resolver. I read in the BIND 9.18.2 ARM that there is a boolean option for RPZ zones called: break-dnssec. The ARM states: ...In that case, RPZ actions are applied regardless of DNSSEC. The name of the clause option reflects the fact