Re: draft-durand-ngtrans-dns-issues-00.txt

Jim Reid <Jim.Reid@nominum.com> Fri, 28 June 2002 11:19 UTC

Received: from nic.cafax.se (nic.cafax.se [192.71.228.17]) by ietf.org (8.9.1a/8.9.1a) with ESMTP id HAA19982 for <dnsop-archive@odin.ietf.org>; Fri, 28 Jun 2002 07:19:40 -0400 (EDT)
Received: from nic.cafax.se (localhost [127.0.0.1]) by nic.cafax.se (8.12.5/8.12.5) with ESMTP id g5SAtgo2002914 for <dnsop-outgoing@nic.cafax.se>; Fri, 28 Jun 2002 12:55:42 +0200 (MEST)
Received: from localhost (localhost [[UNIX: localhost]]) by nic.cafax.se (8.12.5/8.12.5/Submit) id g5SAtgkO002913 for dnsop-outgoing; Fri, 28 Jun 2002 12:55:42 +0200 (MEST)
X-Authentication-Warning: nic.cafax.se: majordom set sender to owner-dnsop@cafax.se using -f
Received: from shell.nominum.com (shell.nominum.com [128.177.192.160]) by nic.cafax.se (8.12.5/8.12.5) with ESMTP id g5SAtfo2002908 for <dnsop@cafax.se>; Fri, 28 Jun 2002 12:55:41 +0200 (MEST)
Received: from shell.nominum.com (localhost [127.0.0.1]) by shell.nominum.com (Postfix) with ESMTP id 34889137F02; Fri, 28 Jun 2002 03:55:40 -0700 (PDT)
To: Shane Kerr <shane@ripe.net>
Cc: Robert Elz <kre@munnari.OZ.AU>, Alain Durand <Alain.Durand@sun.com>, ggm@apnic.net, dnsop@cafax.se
Subject: Re: draft-durand-ngtrans-dns-issues-00.txt
In-Reply-To: Message from Shane Kerr <shane@ripe.net> of "Fri, 28 Jun 2002 11:58:41 +0200." <20020628095841.GF16776@x17.ripe.net>
Date: Fri, 28 Jun 2002 03:55:40 -0700
Message-ID: <44341.1025261740@shell.nominum.com>
From: Jim Reid <Jim.Reid@nominum.com>
Sender: owner-dnsop@cafax.se
Precedence: bulk

>>>>> "Shane" == Shane Kerr <shane@ripe.net> writes:

    >> No.  While technically they're allowed, they make no sense to
    >> actually use.  PTR records (for this purpose) are useful only
    >> if there's some way to verify them.

    Shane> It's also not clear to me how a wildcard PTR is different
    Shane> from (or better than) a NS record.

Well as someone already said, signing wildcard RRs can't be done
easily (if at all) with DNSSEC. "Here's a SIG record for the name that
you looked up even though that name doesn't exist and only matches a
wildcard." At least the NS record(s) and the delegation of the zone
they serve can be signed.