Repository navigation
Expect the negative TTL on the SOA and its RRSIG in authority sections - #49
Merged
Merged
Conversation
erldns now applies RFC 2308 §3 to negative answers: the SOA carried in the authority section, and the RRSIG covering it, are served at the minimum of the SOA TTL and the SOA MINIMUM field. A query for the SOA itself is a positive answer and keeps the zone TTL. Update every spec that pinned the untrimmed TTL in an authority section: example.com goes from 100000 to 86400 and minimal-dnssec.com from 3600 to 300, on both the SOA and the RRSIG covering it. The RRSIG original TTL is part of the signed data and stays as it was.
4 tasks done
AGS4NO
approved these changes
Sep 14, 2026
swagopopotamus
self-requested a review
September 14, 2026 20:15
swagopopotamus
approved these changes
Sep 14, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
erldns is going back to RFC 2308 §3 for negative answers: the SOA in the authority section of an NXDOMAIN or NODATA answer, and the RRSIG covering it, are served at the minimum of the SOA TTL and the SOA MINIMUM field. The answer section of a query for the SOA itself is unchanged, and so is the RRSIG original TTL, which is part of the signed data.
"Going back" is about erldns's history, not the RFC's. RFC 2308 (1998) defined the negative caching TTL this way, RFC 4034 §3 is why the SOA's signature has to move with it, and RFC 9077 (2021), the newest RFC on the subject, extended the same lesser-of rule to NSEC and NSEC3 TTLs rather than replacing it. The specs here that pinned the SOA at its full TTL in an authority section encode a regression: erldns #264 removed the response rewrite in July 2025 while fixing an unrelated TTL mismatch on the stored SOA RRSIG, and these specs were re-pinned to that output. PowerDNS, whose regression tests these specs descend from, trims the TTL exactly as erldns does again now.
This updates the 28 specs across
dnstest_definitions,wildcard_specsandent_specsthat pinned the untrimmed TTL in an authority section:example.comgoes from 100000 to 86400,minimal-dnssec.comfrom 3600 to 300, on the SOA and on the RRSIG covering it. No spec changes in any other way; every affected spec was failing only on the authority TTL against the erldns branch, and all of them pass with it. NSEC TTLs were already at the minimum and do not move.The erldns change is on
fix/rfc2308-negative-soa-ttlin dnsimple/erldns and pins this branch by commit. erldnsimple followsmainhere, so this should land together with the erldnsimple bump to the released erldns, otherwise its integration run fails in between.