tech-net archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]

Re: bind vs glue records



On Thu, 31 Mar 2016, Jeremy C. Reed wrote:

> dig +sit bmb.glbaa.barclays.com. @157.83.102.245
>   (no response)

More information ... a few of the nameservers timeout (don't respond) on 
the cookie (or SIT). And the one that finally responds, returns the 
NXDOMAIN. (If +nocookie, they all do send back an answer.)

Here is an example of a response that could happen:
http://www.kb.cert.org/vuls/id/714121
(CERT issued an advisory because some DNS servers responded with wrong 
message.)

Also see 
https://tools.ietf.org/html/draft-ietf-dnsop-no-response-issue
about problems like this.



Home | Main Index | Thread Index | Old Index