Validating zones as a slave?

Tony Finch dot at dotat.at
Wed Sep 16 12:04:39 UTC 2015


Lars-Johan Liman <liman at netnod.se> wrote:
> each at isc.org:
> > (It has other benefits as well; you don't get spurious AA bits
> > in your client responses.)
>
> Why are AA bits in client responses a negative thing?

Some DNS users (e.g. ssh looking up SSHFP records) can be configured to
trust the AD bit, but you don't get an AD bit if your recursive server is
authoritative for a zone.

Tony.
-- 
f.anthony.n.finch  <dot at dotat.at>  http://dotat.at/
Viking, North Utsire: Easterly 4 or 5, increasing 6 at times. Slight or
moderate, but rough in southwest Viking. Showers later. Good, occasionally
poor later.


More information about the bind-workers mailing list