Hi,

I am looking for a DNS contact at integraonline.com / allstream.net. I tried 
[email protected], but haven't received any replies yet.

Problem is as follows:

It replies with the correct aa=1 bit when dnssec is enabled.

❯ dig ns2.business.allstream.net @ns.integraonline.com. +norec | grep flags
;; flags: qr ra; QUERY: 1, ANSWER: 1, AUTHORITY: 2, ADDITIONAL: 1
; EDNS: version: 0, flags:; udp: 4096

vs

❯ dig ns2.business.allstream.net @ns.integraonline.com. +norec +dnssec | grep 
flags
;; flags: qr aa; QUERY: 1, ANSWER: 1, AUTHORITY: 2, ADDITIONAL: 1
; EDNS: version: 0, flags:; udp: 4096

If anyone can forward this message or get me in touch with them, please do so. 
I am aware of at least one dns resolver (PowerDNS) which refuses to accept 
these RFC violating answers. A customer of mine operates a resolving DNS 
network with a large customer base in Canada, so they are impacted by this.

Kind Regards,

Frank
_______________________________________________
dns-operations mailing list
[email protected]
https://lists.dns-oarc.net/mailman/listinfo/dns-operations

Reply via email to