Skip to content

Expect the negative TTL on the SOA and its RRSIG in authority sections - #49

Merged
NelsonVides merged 1 commit into
mainfrom
fix/rfc2308-negative-soa-ttl
Sep 15, 2026
Merged

NelsonVides merged 1 commit into
mainfrom
fix/rfc2308-negative-soa-ttl

Conversation

@NelsonVides

Copy link
Copy Markdown
Contributor

erldns is going back to RFC 2308 §3 for negative answers: the SOA in the authority section of an NXDOMAIN or NODATA answer, and the RRSIG covering it, are served at the minimum of the SOA TTL and the SOA MINIMUM field. The answer section of a query for the SOA itself is unchanged, and so is the RRSIG original TTL, which is part of the signed data.

"Going back" is about erldns's history, not the RFC's. RFC 2308 (1998) defined the negative caching TTL this way, RFC 4034 §3 is why the SOA's signature has to move with it, and RFC 9077 (2021), the newest RFC on the subject, extended the same lesser-of rule to NSEC and NSEC3 TTLs rather than replacing it. The specs here that pinned the SOA at its full TTL in an authority section encode a regression: erldns #264 removed the response rewrite in July 2025 while fixing an unrelated TTL mismatch on the stored SOA RRSIG, and these specs were re-pinned to that output. PowerDNS, whose regression tests these specs descend from, trims the TTL exactly as erldns does again now.

This updates the 28 specs across dnstest_definitions, wildcard_specs and ent_specs that pinned the untrimmed TTL in an authority section: example.com goes from 100000 to 86400, minimal-dnssec.com from 3600 to 300, on the SOA and on the RRSIG covering it. No spec changes in any other way; every affected spec was failing only on the authority TTL against the erldns branch, and all of them pass with it. NSEC TTLs were already at the minimum and do not move.

The erldns change is on fix/rfc2308-negative-soa-ttl in dnsimple/erldns and pins this branch by commit. erldnsimple follows main here, so this should land together with the erldnsimple bump to the released erldns, otherwise its integration run fails in between.

erldns now applies RFC 2308 §3 to negative answers: the SOA carried in
the authority section, and the RRSIG covering it, are served at the
minimum of the SOA TTL and the SOA MINIMUM field. A query for the SOA
itself is a positive answer and keeps the zone TTL.

Update every spec that pinned the untrimmed TTL in an authority section:
example.com goes from 100000 to 86400 and minimal-dnssec.com from 3600
to 300, on both the SOA and the RRSIG covering it. The RRSIG original
TTL is part of the signed data and stays as it was.
@NelsonVides NelsonVides self-assigned this Sep 14, 2026
@NelsonVides NelsonVides added the bug Code defect or incorrect behavior label Sep 14, 2026
@NelsonVides
NelsonVides requested a review from a team September 14, 2026 19:38
@swagopopotamus
swagopopotamus self-requested a review September 14, 2026 20:15
@NelsonVides
NelsonVides merged commit 3abd2ab into main Sep 15, 2026
2 checks passed
@NelsonVides
NelsonVides deleted the fix/rfc2308-negative-soa-ttl branch September 15, 2026 06:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Code defect or incorrect behavior

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants