This repository has been archived by the owner on Jun 7, 2024. It is now read-only.
test that a RRset whose TTL values differ from RRSIG's 'Original TTL' field is rejected #62
Labels
dnssec
Conformance to DNSSEC RFCs
section 3.1.8.1 (Signature Calculation) of RFC4034 says
NOTE: the RFC may be referring to the TTL values written in the zone file because this requirement does not uphold in records received by a resolver / nameserver client. for example:
3600
is the original TTL value but it does not match the TTL value of A record nor the TTL of the RRSIG recordThe text was updated successfully, but these errors were encountered: