DNSSEC: Perché i RRSIG sono restituiti nella sezione "Risposta" e "Ulteriori"?

2

Guardando le tracce di Wireshark delle risposte DNSSEC, vedo che RRSIG viene restituito nella sezione "Rispondi", anche se non faceva parte della query.

Perché non viene restituito nella sezione "Additional", che è progettata in modo preciso per ulteriori informazioni oltre alla query?

    
posta SRobertJames 08.06.2015 - 03:11
fonte

1 risposta

2

Sembra che l'idea sia quella di mantenere i RR e le loro firme vicine.

RFC 4035, Sezione 3.1.1, inclusi i RRSIG RR in una risposta

3.1.1. Including RRSIG RRs in a Response

When responding to a query that has the DO bit set, a security-aware authoritative name server SHOULD attempt to send RRSIG RRs that a security-aware resolver can use to authenticate the RRsets in the response. A name server SHOULD make every attempt to keep the RRset and its associated RRSIG(s) together in a response. Inclusion of RRSIG RRs in a response is subject to the following rules:

o When placing a signed RRset in the Answer section, the name server MUST also place its RRSIG RRs in the Answer section. The RRSIG RRs have a higher priority for inclusion than any other RRsets that may have to be included. If space does not permit inclusion of these RRSIG RRs, the name server MUST set the TC bit.

o When placing a signed RRset in the Authority section, the name server MUST also place its RRSIG RRs in the Authority section. The RRSIG RRs have a higher priority for inclusion than any other RRsets that may have to be included. If space does not permit inclusion of these RRSIG RRs, the name server MUST set the TC bit.

o When placing a signed RRset in the Additional section, the name server MUST also place its RRSIG RRs in the Additional section. If space does not permit inclusion of both the RRset and its associated RRSIG RRs, the name server MAY retain the RRset while dropping the RRSIG RRs. If this happens, the name server MUST NOT set the TC bit solely because these RRSIG RRs didn't fit.

    
risposta data 08.06.2015 - 07:11
fonte

Leggi altre domande sui tag