North American Network Operators Group

Date Prev | Date Next | Date Index | Thread Index | Author Index | Historical

Re: A list of (mostly) technical consequences of TLD wildcards

  • From: Paul Vixie
  • Date: Sat Sep 27 11:44:16 2003

> Makes me wonder why Verisign didn't use a (less harmful?) CNAME wildcard ...

The CNAME algorythm in RFC1034 looks for CNAMEs before it looks for wildcards,
meaning that the target of a CNAME could end up matching a wildcard, but the
CNAME owner itself won't be found using the wildcarding rules.  see [4.3.2].

What this means is, there is no such thing as a wildcard CNAME.
-- 
Paul Vixie