[Opendnssec-develop] How to handle TTL < SOA Minimum

Jakob Schlyter jakob at kirei.se
Wed Jul 28 05:59:07 UTC 2010

On 23 jul 2010, at 10.42, Alex Dalitz wrote:

>>> Now it comes, this is a TTL that is lower than the SOA MINIMUM. How
>>> should we handle those TTLs? Must the signer use the explicit TTL or the
>>> SOA MINIMUM in this case? I think so.
>> I think so too.
> To avoid any confusion : I think the SOA Minimum should be used in this case - NOT the explicit TTL.

how does BIND handle this?

I'm usually a believer in "garbage in, garbage out", so my gut feeling is that the signer should use the explicit TTL.


More information about the Opendnssec-develop mailing list