Re: [DNSOP] AD bit set by authoritative servers [was: Re: More solicitation for feedback on dns64]

2009-03-27 Thread Jelte Jansen
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Edward Lewis wrote: > At 1:28 +0100 3/27/09, Holger Zuleger wrote: > >> So why doesn't an authoritative name server set the AD bit on answers >> to queries with the DO flag set? > > Good question. Perhaps the authoritative server does not have DNSSE

Re: [DNSOP] AD bit set by authoritative servers [was: Re: More solicitation for feedback on dns64]

2009-03-26 Thread Mark Andrews
In message , Edward Lewis writes: > At 1:28 +0100 3/27/09, Holger Zuleger wrote: > > >So why doesn't an authoritative name server set the AD bit on > >answers to queries with the DO flag set? > > Good question. Perhaps the authoritative server does not have DNSSEC enabled > ? > > (BIND specif

Re: [DNSOP] AD bit set by authoritative servers [was: Re: More solicitation for feedback on dns64]

2009-03-26 Thread Edward Lewis
At 1:28 +0100 3/27/09, Holger Zuleger wrote: So why doesn't an authoritative name server set the AD bit on answers to queries with the DO flag set? Good question. Perhaps the authoritative server does not have DNSSEC enabled? (BIND specific - in recent versions of BIND, since Feb 2007, if d

[DNSOP] AD bit set by authoritative servers [was: Re: More solicitation for feedback on dns64]

2009-03-26 Thread Holger Zuleger
Regarding the original thread, I fully support the opinion of Andrew and Edward. But regarding the AD bit discussion, I wondered if the following statement is true for authoritative name servers: Edward Lewis wrote: A bunch of people, in the past wrote this stuff: > So AD doesn't mean "I va