 | reply to David
Re: I tested this a bit last night at the house= My results The jar based test is somewhat misleading.
The problem occurs only when the resolver ADVERTISES that it wants DNSSEC replies, AND advertises a reply size larger than it can actually handle, the .jar test doesn't make this distinction.
Thus, eg, both Google Public DNS and OpenDNS don't advertise requests for DNSSEC replies and (at least when Google Public DNS does), are able to receive replies equal to the advertised reply size, so they are actually completely unaffected. |