[Opendnssec-user] Adhering to RFC 9276 Sec. 3.1

Antonio Prado antonio at prado.it
Fri Oct 25 18:50:51 UTC 2024


On 10/25/24 3:45 PM, Bruno Blanes via Opendnssec-user wrote:

> I’ve been trying to set OpenDNSSEC to generate the NSEC3 parameter with 
> an empty salt and zero iterations (as per RFC 9276 Sec. 3.1), but to no 
> avail. I have tried setting <Iterations> to zero as well as <Salt> 
> length parameter, but couldn’t get it working.
> 
> Could some kind angel help me out here, please?

hi,

<NSEC3>
        <Hash>
          <Algorithm>1</Algorithm>
          <Iterations>0</Iterations>
          <Salt length="0"/>
        </Hash>
</NSEC3>

then apply the policy and wait
--
antonio
-------------- next part --------------
A non-text attachment was scrubbed...
Name: OpenPGP_signature.asc
Type: application/pgp-signature
Size: 203 bytes
Desc: OpenPGP digital signature
URL: <http://lists.opendnssec.org/pipermail/opendnssec-user/attachments/20241025/030bce72/attachment.bin>


More information about the Opendnssec-user mailing list