Skip to content

Verify "key tag" field in RRSIG, DS and CERT RRs(?) #87

@k0ekk0ek

Description

@k0ekk0ek

RFC4034, Appendix B outlines an algorithm to use for coming up with the "key tag". To my knowledge, at least in NSD, the value is not verified. Strictly speaking, it doesn't have to, but I'm wondering how and if the "key tag" is actually used (it's meant for quick selection). For RRSIG and DS records there's decent tooling to sign a zone and users probably do not have to worry about coming up with it, for CERT records, that doesn't seem to be the case.

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions