Re: XFR killed by security

2024-03-04 Thread Peter
On Mon, Mar 04, 2024 at 03:43:48PM +0100, Ondřej Surý wrote: ! > On 4. 3. 2024, at 14:55, Peter wrote: ! > ! > I don't find it really surprizing that XFR would contain "multiple ! > RRSIG entries". ! ! Unfortunately, this is obviously surprising to the vendor of the security device. This needs

Re: XFR killed by security

2024-03-04 Thread Ondřej Surý
> On 4. 3. 2024, at 14:55, Peter wrote: > > I don't find it really surprizing that XFR would contain "multiple > RRSIG entries". Unfortunately, this is obviously surprising to the vendor of the security device. This needs to be fixed there, not here. As for the CVE, you have the number that ca

XFR killed by security

2024-03-04 Thread Peter
Hi folks, a few days ago I apparently lost the beneficence of my zone feeds, and XFR started to get into timeout. Looking at the usual culprits I then found this: DNS Response containing multiple DNSSEC RRSIG Entries (Algorithm 14) - Possible CVE-2023-50387 Activity [Classification: De