Lines Matching refs:nsec3
2134 /** true if domain has only nsec3 */
2254 /* no direct answer from nsec3-only domains */
2598 /* skip unknown flags (dynamic signer is recalculating nsec3 chain) */
2693 /* because canonical ordering and b32 nsec3 ordering are the same.
2694 * this is a good lookup to find the nsec3 name. */
2696 /* but we may have to skip non-nsec3 nodes */
2698 * separate nsec3 tree with nsec3 nodes */
2791 struct auth_rrset* nsec3;
2793 nsec3 = az_domain_rrset(node, LDNS_RR_TYPE_NSEC3);
2794 if(!nsec3) return 1; /* if no nsec3 RR, skip it */
2795 if(!msg_add_rrset_ns(z, region, msg, node, nsec3)) return 0;
2799 /** add NSEC3 records to the zone for the nsec3 proof.
2804 * always enabled: include nsec3 proving about the Closest Encloser.
2825 /* find parameters of nsec3 proof */
2827 return 1; /* no nsec3 */
2830 * proof nsec3, this has to be an exact match nsec3. */
2855 /* find nsec3 that matches or covers it */
2871 /* find nsec3 that matches or covers it */
3088 * wildcard qname denial needs to have a CE nsec3. */