[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: question about dnssec-protocol-04



At Mon, 22 Dec 2003 22:19:04 -0500, David Blacka wrote:
> 
> On Monday 22 December 2003 3:17 pm, Rob Austein wrote:
> 
> > > I feel sure that I have just forgotten the discussion about this, but why
> > > does this restriction exist?  What harm would NSEC records of this sort
> > > cause?
> > >
> > > It is true that I cannot think of any useful reason to do this, but
> > > forbidding such NSEC records should have some real problem associated
> > > with it.
> >
> > Empty non-terminals.
> 
> I know what empty non-terminals are, but I have know idea what you are talking 
> about.

The restriction is there to make sure that signer and verifier agree
on whether or not empty non-terminal nodes are supposed to have signed
NSEC RRs.

--
to unsubscribe send a message to namedroppers-request@ops.ietf.org with
the word 'unsubscribe' in a single line as the message text body.
archive: <http://ops.ietf.org/lists/namedroppers/>