Question about DNSSEC

Bob McDonald bmcdonaldjr at gmail.com
Thu Oct 31 22:15:16 UTC 2024


If a host is defined as a CNAME chain where the domain of the host is
DNSSEC signed but the domain(S) of the target(s) in the CNAME chain are
not, does that mean that the entry really isn't DNSSEC protected?

I can list an example dig for the host in question but I'm reluctant to do
so as it's a US gov host.

Please advise.

Regards,

Bob
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.isc.org/pipermail/bind-users/attachments/20241031/bc2001a5/attachment.htm>


More information about the bind-users mailing list