Skip Menu |

This queue is for tickets about the Net-DNS-SEC CPAN distribution.

Report information
The Basics
Id: 15662
Status: resolved
Priority: 0/
Queue: Net-DNS-SEC

People
Owner: Nobody in particular
Requestors: olaf [...] net-dns.sec
Cc:
AdminCc:

Bug Information
Severity: Important
Broken in: 0.12_02
Fixed in: (no value)



Subject: asterisk not detected in label count.
One of the differences in the output from our signers is that the labelcount in the signature over a wildcard RRSET is one-off. It seems that the RRSIG.pm code does not detect the asterix label and assume it is just another label. From rfc4035 section 2.2 (but you prolly know this) The RRSIG Labels field is equal to the number of labels in the RRset owner name, not counting the null root label and not counting the leftmost label if it is a wildcard.