Re: Question about TSIG, AD/AA, and AXFR

Jakob Schlyter <jakob@crt.se> Tue, 17 July 2001 20:47 UTC

Received: from psg.com (exim@psg.com [147.28.0.62]) by ietf.org (8.9.1a/8.9.1a) with SMTP id QAA09973 for <dnsext-archive@lists.ietf.org>; Tue, 17 Jul 2001 16:47:51 -0400 (EDT)
Received: from lserv by psg.com with local (Exim 3.31 #1) id 15MaoL-00041z-00 for namedroppers-data@psg.com; Tue, 17 Jul 2001 12:47:13 -0700
Received: from h-135-207-10-122.research.att.com ([135.207.10.122] helo=roam.psg.com) by psg.com with esmtp (Exim 3.31 #1) id 15MaoL-00041t-00 for namedroppers@ops.ietf.org; Tue, 17 Jul 2001 12:47:13 -0700
Received: from randy by roam.psg.com with local (Exim 3.30 #1) id 15MaoK-0000TA-00 for namedroppers@ops.ietf.org; Tue, 17 Jul 2001 15:47:12 -0400
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
From: Jakob Schlyter <jakob@crt.se>
To: Edward Lewis <lewis@tislabs.com>
Cc: namedroppers@ops.ietf.org
Subject: Re: Question about TSIG, AD/AA, and AXFR
In-Reply-To: <v0313030eb779efd43e81@[208.58.212.166]>
Sender: owner-namedroppers@ops.ietf.org
Precedence: bulk
Message-Id: <E15MaoL-00041z-00@psg.com>
Date: Tue, 17 Jul 2001 12:47:13 -0700
Content-Transfer-Encoding: 7bit

On Tue, 17 Jul 2001, Edward Lewis wrote:

> From you message it sounds like no one should trust data with the AA bit,
> as this means the authentication has not been checked.  This is an ironic
> conclusion, as we've been assigning more credibility to AA'd data.  (Once
> again, the credibility vs. authenticated issue arises.)

the nameserver should never set the AD bit without actually verifying the
data. some earlier version of bind did set AD if the server itself were
authorative. I belive this is wrong - data shouldn't be checked on load,
it should be checked on query.

I think the AA-bit could be trustworthy for very simple resolvers that,
for some reason, do trust their local resolver.

	jakob



to unsubscribe send a message to namedroppers-request@ops.ietf.org with
the word 'unsubscribe' in a single line as the message text body.