I'm looking for a bit of DNS help here... We've been doing a bit of work that involves looking up the real authoritative nameservers for domains that we believe we are authoritative for, and have run into a spot of trouble when it comes to looking up ca. sub-domains. Could I ask people with domains ending in .ca to do lookups of type NS for that/those domain(s) against all the ca. nameservers, and let me know if you see anything weird? Specifically, can you look at the ANCOUNT response? Just looking to see if my DNS understanding is way off whack, or if there really /is/ something funky going on with a couple of the servers. TIA... - Damian P.S. I /have/ contacted the organization in question, but received a response that was *entirely* puzzling, which is why I'm asking here...
From: "Damian Gerow" <damian@sentex.net>
Could I ask people with domains ending in .ca to do lookups of type NS for that/those domain(s) against all the ca. nameservers, and let me know if you see anything weird? Specifically, can you look at the ANCOUNT response?
Just looking to see if my DNS understanding is way off whack, or if there really /is/ something funky going on with a couple of the servers.
I don't see anything wrong in particular, apart from a few of the servers responding with glue data in the answer-section, instead of the authority section. I assume this is what you're refering to. This is correct behavior, glue data is not an authorative answer and should therefore not be in the answer section. This was a misimplementation in BIND prior to version 9. Best regards, Kandra Nygårds
participants (2)
-
Damian Gerow
-
Kandra Nygårds