Re: [Pdns-users] pdns_recursor and records in additional section of replies

2019-01-23 Thread Remi Gacogne
On 1/23/19 2:08 PM, Thomas Mieslinger wrote: > Lets take the output of > > dig +dnssec ns-de.ui-dns.de @a.nic.de > > as an example. If the additional section was tweaked, pdns_recursor has > no real chance to detect this. That's actually a very good example because unless I'm mistaken, ever

Re: [Pdns-users] pdns_recursor and records in additional section of replies

2019-01-23 Thread Thomas Mieslinger
Hi Remi, On 1/23/19 10:04 AM, Remi Gacogne wrote: [..] >> In short I would like that pdns_recursor does not use information from additional sections. Just like pdns authoritative 4.1.x does not generate additional sections anymore. Completely ignoring additional records would break zones that

Re: [Pdns-users] pdns_recursor and records in additional section of replies

2019-01-23 Thread Remi Gacogne
Hi Thomas, On 1/23/19 8:01 AM, Thomas Mieslinger wrote: > I would like to better understand how pdns_recursor 4.1.x deals with > records in the additional section of replies it gets from authoritative > Servers. These records, if the recursor considers that the authoritative server is allowed to

[Pdns-users] pdns_recursor and records in additional section of replies

2019-01-22 Thread Thomas Mieslinger
Hi, I would like to better understand how pdns_recursor 4.1.x deals with records in the additional section of replies it gets from authoritative Servers. In short I would like that pdns_recursor does not use information from additional sections. Just like pdns authoritative 4.1.x does not g