Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Verify "key tag" field in RRSIG, DS and CERT RRs(?) #87

Open
k0ekk0ek opened this issue Aug 2, 2023 · 0 comments
Open

Verify "key tag" field in RRSIG, DS and CERT RRs(?) #87

k0ekk0ek opened this issue Aug 2, 2023 · 0 comments
Labels
enhancement New feature or request

Comments

@k0ekk0ek
Copy link
Contributor

k0ekk0ek commented Aug 2, 2023

RFC4034, Appendix B outlines an algorithm to use for coming up with the "key tag". To my knowledge, at least in NSD, the value is not verified. Strictly speaking, it doesn't have to, but I'm wondering how and if the "key tag" is actually used (it's meant for quick selection). For RRSIG and DS records there's decent tooling to sign a zone and users probably do not have to worry about coming up with it, for CERT records, that doesn't seem to be the case.

@k0ekk0ek k0ekk0ek added the enhancement New feature or request label Feb 16, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request
Projects
None yet
Development

No branches or pull requests

1 participant