If there are multiple DS records with each using a different but RFC-compliant algorithm and digest type, is there any way to predict how real world validators will select one?
I've tried to, for example, to review what the default behavior BIND would be, but I'm not familiar enough to know where to start to understand how it would resolve.
Example:
A zone has the following valid DS record algorithm and digest types:
Algorithm | Digest type |
---|---|
13 | 2 |
7 | 2 |
8 | 4 |
How does a validator choose which DS record to use?
0 Answers