Hi Klaus,
Knot returns the NOTAUTH rcode intentionally as it also means "Not Authorized"
(
https://www.iana.org/assignments/dns-parameters/dns-parameters.xhtml#dns-pa…).
There was a similar discussion on this topic in the past
https://lists.dns-oarc.net/pipermail/dns-operations/2016-June/015025.html
Regards,
Daniel
On 01/08/2018 09:09 AM, Klaus Darilion wrote:
Hi!
Knot 2.6.3: When an incoming NOTIFY does not match any ACL the NOTIFY is
replied with "notauth" although the zone is configured. I would have
expected that Knot should response with "refused" in such a scenario. Is
the notauth intended? From operational view a "refuses" would easy
debugging.
regards
Klaus