You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
When using SOA-EDIT, the edited serial number is used for important things, like SOA queries and zone transfers.
However, the backend database's original serial number is used for the SOA record in NXDOMAIN responses, and for NODATA responses that are not for the zone apex.
Zone apex NODATA responses also use the edited serial number.
I'm using DNSSEC; both SOA records are apparently signed correctly.
The SOA serial number in a negative response doesn't matter for anything, but creative resolvers will cache it as the zone's real SOA record.
Environment
Operating system: Ubuntu 16.04
Software version: 0.0.15744+0.g7c94d361cd and 0.0.15793+0.g732fda289a
Short description
When using
SOA-EDIT
, the edited serial number is used for important things, likeSOA
queries and zone transfers.However, the backend database's original serial number is used for the
SOA
record inNXDOMAIN
responses, and for NODATA responses that are not for the zone apex.Zone apex NODATA responses also use the edited serial number.
I'm using DNSSEC; both
SOA
records are apparently signed correctly.The
SOA
serial number in a negative response doesn't matter for anything, but creative resolvers will cache it as the zone's realSOA
record.Environment
Steps to reproduce
dig +dnssec +norecurse dns-l.mn9.us @ns2.mattnordhoffdns.org
dig +dnssec +norecurse dns-l.mn9.us soa @ns2.mattnordhoffdns.org
dig +dnssec +norecurse foo.dns-l.mn9.us aaaa @ns2.mattnordhoffdns.org
dig +dnssec +norecurse nxdomain.dns-l.mn9.us @ns2.mattnordhoffdns.org
sudo pdnsutil set-meta dns-l.mn9.us SOA-EDIT INCEPTION-INCREMENT
sudo pdnsutil set-nsec3 dns-l.mn9.us "1 0 0 -"
sudo pdnsutil secure-zone dns-l.mn9.us
Expected behaviour
The edited serial number everywhere.
Actual behaviour
Both serial numbers.
Other information
Related code?
pdns/pdns/packethandler.cc
Lines 969 to 1007 in c6bdd14
pdns/pdns/packethandler.cc
Lines 1425 to 1435 in c6bdd14
Zone:
The text was updated successfully, but these errors were encountered: