Loading...
Loading...
DNS response is not signed for DNSSEC zone for DNSSEC request.
DNS response is not signed.
1. A DNSSEC zone exists. 2. Return Code on Failure is enabled and SOA Negative Caching TTL is set to 0. 3. A query hits that wideIP and does not get a pool member selected.
SOA Negative Caching TTL set to a number larger than 0.
DNSSEC response is signed when failure-rcode-response is enabled, and relevant records are returned.
SOA records are included in the DNS response even for queries with a negative TTL (failure-rcode-response) from a WideIP that has no pools attached. Additionally: 1. NSEC3 and RRSIG records are correctly generated and signed for DNSSEC validation. 2. DNS validating clients no longer reject the response; the query completes successfully with DNSSEC validation.
F5 Integration
Learn more about where this data comes from
BugZero Plan
Streamline upgrades with automated vendor bug scrubs
BugZero Prevent
Wish you caught this bug sooner? Get proactive today.