How to validate DNSSEC signatures – zone cuts?
RFC 4035, section 5.3.1 lays out the rules for validating DNSSEC RRSIG records:
The RRSIG RR and the RRset MUST have the same owner name and the same class.
The RRSIG RR’s Signer’s Name field MUST be the name of the zone that contains th… Continue reading How to validate DNSSEC signatures – zone cuts?