Re: DNSSEC validation via AD bit?

2022-01-30 Thread Mark Andrews
> On 31 Jan 2022, at 10:45, Gregory Shapiro via bind-users > wrote: > > sendmail's implementation of DANE determines whether DNSSEC validation was > successful based on the presence of the AD bit in the response to the DANE > record lookup. > > An equivalent dig lookup would be: > >%

DNSSEC validation via AD bit?

2022-01-30 Thread Gregory Shapiro via bind-users
sendmail's implementation of DANE determines whether DNSSEC validation was successful based on the presence of the AD bit in the response to the DANE record lookup. An equivalent dig lookup would be: % dig TLSA _25._tcp.smtp.gshapiro.net. ... ;; Got answer: ;; ->>HEADER<<- opc