The following errata report has been verified for RFC6672, "DNAME Redirection in the DNS". -------------------------------------- You may review the report below and at: https://www.rfc-editor.org/errata/eid5298 -------------------------------------- Status: Verified Type: Editorial Reported by: Pieter Lexis <pieter.lexis@powerdns.com> Date Reported: 2018-03-2 Verified by: Eric Vyncke (IESG) Section: Original Text ------------- ;; Header: QR AA RCODE=3(NXDOMAIN) ;; OPT PSEUDOSECTION: ; EDNS: version: 0, flags: do; udp: 4096 ;; Question cee.example.com. IN A ;; Authority bar.example.com. NSEC dub.example.com. A DNAME bar.example.com. RRSIG NSEC [valid signature] Corrected Text -------------- ;; Header: QR AA RCODE=3(NXDOMAIN) ;; OPT PSEUDOSECTION: ; EDNS: version: 0, flags: do; udp: 4096 ;; Question cee.example.com. IN A ;; Authority bar.example.com. NSEC dub.example.com. A DNAME RRSIG NSEC bar.example.com. RRSIG NSEC [valid signature] Notes ----- The NSEC record in the original text would in no case be valid as it denies it's own existence and the existence of the RRSIG, while the text indicates that " the validator can see that it is a BOGUS reply from an attacker that collated existing records from the DNS to create a confusing reply". This indicates that NSEC and RRSIG should be set in the NSEC bitmap Edit: Thread - https://www.ietf.org/mail-archive/web/dnsext/current/msg13879.html -------------------------------------- RFC6672 (draft-ietf-dnsext-rfc2672bis-dname-26) -------------------------------------- Title : DNAME Redirection in the DNS Publication Date : June 2012 Author(s) : S. Rose, W. Wijngaards Category : PROPOSED STANDARD Source : DNS Extensions Area : Internet Stream : IETF Verifying Party : IESG
