Answers from subzone even when superzone has a delegation elsewhere

Friesen, Don CITZ:EX Don.Friesen at gov.bc.ca
Tue Feb 13 14:31:32 UTC 2024


Andy,  You do also have the A record glue for elsewhere.example.com in the example.com zone, right?  Just checking.

Don Friesen

-----Original Message-----
From: bind-users <bind-users-bounces at lists.isc.org> On Behalf Of Andy Smith
Sent: Tuesday, February 13, 2024 6:23 AM
To: bind-users at lists.isc.org
Subject: Answers from subzone even when superzone has a delegation elsewhere

[You don't often get email from andy at strugglers.net. Learn why this is important at https://aka.ms/LearnAboutSenderIdentification ]

[EXTERNAL] This email came from an external source. Only open attachments or links that you are expecting from a known sender.


Hi,

I'm running:

9.16.44-Debian (Extended Support Version) <id:cd2b460>

If I have zones example.com and sub.example.com both loaded, but example.com contains a record:

sub.example.com. NS elsewhere.example.com.

(i.e. the subzone is delegated to some other server)

is it normal and expected that a query for foo.sub.example.com should be answered NXDOMAIN from the auth servers for example.com because the zone sub.example.com is also loaded there (and has no "foo" RR), rather than the delegation to elsewhere.example.com be followed?

If that is expected, is there configuration that can alter that behaviour, or is that RFC required behaviour that should not be altered?

Thanks,
Andy
--
Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list

ISC funds the development of this software with paid support subscriptions. Contact us at https://www.isc.org/contact/ for more information.


bind-users mailing list
bind-users at lists.isc.org
https://lists.isc.org/mailman/listinfo/bind-users


More information about the bind-users mailing list