Re: [Pdns-users] Additional NSEC3-Record in Response - DNSSEC Validation fails

2011-08-22 Thread bert hubert
On Mon, Aug 22, 2011 at 03:41:57PM +0200, Michael Braunoeder wrote: > I did some more DNSSEC-testing and found another bug: I was starting to worry that too little bugs were being found ;-) > When querying for an undefined records, PDNS adds an additional > NSEC3-Record into the response and the

[Pdns-users] Additional NSEC3-Record in Response - DNSSEC Validation fails

2011-08-22 Thread Michael Braunoeder
Hi, I did some more DNSSEC-testing and found another bug: My setup looks like this: Bind accting as Master server, serving a presigned zone. PDNS 3.0 accting as Slave server, PRESIGNED=1 and NSEC3PARAM is set in Domainmetatable. When querying for an undefined records, PDNS adds an additional