Re: [Add] Zone ownership in DNS server discovery

"Vinny Parla (vparla)" <vparla@cisco.com> Fri, 11 September 2020 00:44 UTC

Return-Path: <vparla@cisco.com>
X-Original-To: add@ietfa.amsl.com
Delivered-To: add@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 6339E3A1275 for <add@ietfa.amsl.com>; Thu, 10 Sep 2020 17:44:19 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -9.598
X-Spam-Level:
X-Spam-Status: No, score=-9.598 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_MED=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001, USER_IN_DEF_DKIM_WL=-7.5] autolearn=unavailable autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=cisco.com header.b=ZzLn6WAm; dkim=fail (1024-bit key) reason="fail (body has been altered)" header.d=cisco.onmicrosoft.com header.b=VFQ5SEJ7
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id SjshmkcdH8tJ for <add@ietfa.amsl.com>; Thu, 10 Sep 2020 17:44:17 -0700 (PDT)
Received: from alln-iport-4.cisco.com (alln-iport-4.cisco.com [173.37.142.91]) (using TLSv1.2 with cipher DHE-RSA-SEED-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id DF5633A1271 for <add@ietf.org>; Thu, 10 Sep 2020 17:44:16 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cisco.com; i=@cisco.com; l=16060; q=dns/txt; s=iport; t=1599785056; x=1600994656; h=from:to:cc:subject:date:message-id:references: in-reply-to:mime-version; bh=iCAZ/R1SJNHw3EN7CvoVgdItNcLIjf1Nf7RZRMB1mYc=; b=ZzLn6WAmLDGay/lmSq5SD9gc/z9dG5oakMoRCYjCzqU+H8VqwD+lMqx3 1NSukGkwCg3VKyLdEt9XNIaEPpRsZXuZr3UD29IuG2pyH012tMVpkMf75 RZFi1tEFSE7lw50chgPyGXQx4dV5RSHHkGxdeFd704zymWsBR2sGPn+Gl Y=;
X-Files: smime.p7s : 3980
IronPort-PHdr: 9a23:kRkN4h1VOgNg6kofsmDT+zVfbzU7u7jyIg8e44YmjLQLaKm44pD+JxWFuadhiVbTVsPa5u5Kze3MvPOoVW8B5MOHt3YPONxJWgQegMob1wonHIaeCEL9IfKrCk5yHMlLWFJ/uX3uN09TFZXyYlTIqTuz4CIcXBLlOlk9KuH8AIWHicOx2qi78IHSZAMdgj27bPtyIRy6oB+XuNMRhN5pK706zV3CpX4bdg==
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-Anti-Spam-Result: A0BYAQAHx1pf/49dJa1fHAEBAQEBAQcBARIBAQQEAQFAgT4EAQELAYEiL1EHcCwtLyyHfgONcodgjCOEboJTA1UEBwEBAQoDAQEfCgQCBAEBhEsCgh0CJDcGDgIDAQELAQEFAQEBAgEGBG2FXAyFcgEBAQEDEhsTAQEsCwEPAgEIEAEEAQEvAjAXAQUIAgQBDQUIBhSDAAWBfk0DHw8BqXoCgTmIYXSBNIMBAQEFhRQYggkHAwaBOAGBUoEeijsbgUE/gVSCHy4+glwEgUUaK4Mdgi2QM4oAgRmKL492gQgKgmWEP4JdgU+RbaBbkHeBXYNuhmCVCwIEAgQFAg4BAQWBaiQNHYEtcBU7gmkfMRcCDY4fDBeDToQ+hhh0AhgBHAIGCgEBAwl8jloBAQ
X-IronPort-AV: E=Sophos;i="5.76,413,1592870400"; d="p7s'?scan'208,217";a="540023925"
Received: from rcdn-core-7.cisco.com ([173.37.93.143]) by alln-iport-4.cisco.com with ESMTP/TLS/DHE-RSA-SEED-SHA; 11 Sep 2020 00:44:15 +0000
Received: from XCH-RCD-005.cisco.com (xch-rcd-005.cisco.com [173.37.102.15]) by rcdn-core-7.cisco.com (8.15.2/8.15.2) with ESMTPS id 08B0iFNY018977 (version=TLSv1.2 cipher=AES256-SHA bits=256 verify=FAIL); Fri, 11 Sep 2020 00:44:15 GMT
Received: from xhs-rtp-001.cisco.com (64.101.210.228) by XCH-RCD-005.cisco.com (173.37.102.15) with Microsoft SMTP Server (TLS) id 15.0.1497.2; Thu, 10 Sep 2020 19:44:14 -0500
Received: from xhs-aln-002.cisco.com (173.37.135.119) by xhs-rtp-001.cisco.com (64.101.210.228) with Microsoft SMTP Server (TLS) id 15.0.1497.2; Thu, 10 Sep 2020 20:44:13 -0400
Received: from NAM10-MW2-obe.outbound.protection.outlook.com (173.37.151.57) by xhs-aln-002.cisco.com (173.37.135.119) with Microsoft SMTP Server (TLS) id 15.0.1497.2 via Frontend Transport; Thu, 10 Sep 2020 19:44:13 -0500
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=ePnp3XbBEnEyYJbh1hqzxagjGraXpn6QKBH9uCp9nDQR7CLtfOmz0pq+ThxlpYMplKe9qd5zFJzXBysIXPx0+AkM5pzOQmYMqod6tfhURjeUlubyS0SFkvKjOF0enAO/+ZZ9OglozLTc2wziHpClwko7yAai9wZIFHPDvQ+5/oHCg2ixp77A5+9Tc87vmMO3ijmThDyt6gm9NhQDgEAFow9fTGCJjkrBPV3jwrMaFUOp5otYtyGQRkYQsLoYqZNAjToI6uvk1yGjXttgH87Mb7Pe8tbIAOVsR+/GgTRdCcPSCGVEszig41W/gbKxvRxU2AgICpQuk9+Q+N6SnL2SBQ==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=iho9fTjtWfDgLPpZEIbKE4HcJVxKhO7Z9XIo3M0QK0k=; b=TS5QhAFivozHmHxTXXaVbLc9XGIJoq1FhC2si3wABpRluQynOlDJm2eQg5yAk+q5kr6NaicG5vLg+cnE6YCFNSFcz/bYMJ53nrdUhk840An+vSyriaVhC0R4FCv7PAiQAPfcDzrjfAoaw1QinZC6TxhqjkTWKCsHfoekQn6tV22HsVSQ82UERJYlnzr5zc2uBy4QjQ9lEOuCYekcWY7mrMfTIO8a1USPogeXJY4PTieRT9xvaVmG643BOSl5jzkeAZLcweTNWmK5JMNTGqMRXekXtjQerD2G+qMwClOUWZRpBoU8K0DmWTKmU0QKtxyuTYlpff8oOwfRNauUtY9z0Q==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=cisco.com; dmarc=pass action=none header.from=cisco.com; dkim=pass header.d=cisco.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cisco.onmicrosoft.com; s=selector2-cisco-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=iho9fTjtWfDgLPpZEIbKE4HcJVxKhO7Z9XIo3M0QK0k=; b=VFQ5SEJ7rGKAZzVhHddA6iMhk+pd9RqaLLn60kZkE1JmAoNe05u8B3bK2MLdJShfNkjhtG07RuGN7RiijziaBmyVXuNVYehNgCwLbRlG8AjMec3Tr2xPVFvWs3nFKn7K70tHXOu2niawbf06uMXthJGw+Lye8z2g6OzywzG/HR4=
Received: from MN2PR11MB4760.namprd11.prod.outlook.com (2603:10b6:208:266::22) by BL0PR11MB3217.namprd11.prod.outlook.com (2603:10b6:208:63::25) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.3370.16; Fri, 11 Sep 2020 00:44:12 +0000
Received: from MN2PR11MB4760.namprd11.prod.outlook.com ([fe80::98b:4104:2283:868]) by MN2PR11MB4760.namprd11.prod.outlook.com ([fe80::98b:4104:2283:868%8]) with mapi id 15.20.3370.016; Fri, 11 Sep 2020 00:44:12 +0000
From: "Vinny Parla (vparla)" <vparla@cisco.com>
To: Tommy Jensen <Jensen.Thomas=40microsoft.com@dmarc.ietf.org>, "Vinny Parla (vparla)" <vparla=40cisco.com@dmarc.ietf.org>
CC: Jim Reid <jim@rfc1035.com>, ADD Mailing list <add@ietf.org>
Thread-Topic: Zone ownership in DNS server discovery
Thread-Index: AQHWh8pTGUbKKQ5KbE2JxT3FmVDZ5KlimQCg
Date: Fri, 11 Sep 2020 00:44:12 +0000
Message-ID: <MN2PR11MB4760BBB33ACC67FFE6873482D8240@MN2PR11MB4760.namprd11.prod.outlook.com>
References: <CH2PR00MB0779A2F5B37BEA18CC174A72FA271@CH2PR00MB0779.namprd00.prod.outlook.com>
In-Reply-To: <CH2PR00MB0779A2F5B37BEA18CC174A72FA271@CH2PR00MB0779.namprd00.prod.outlook.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: yes
X-MS-TNEF-Correlator:
msip_labels: MSIP_Label_f42aa342-8706-4288-bd11-ebb85995028c_Enabled=True; MSIP_Label_f42aa342-8706-4288-bd11-ebb85995028c_SiteId=72f988bf-86f1-41af-91ab-2d7cd011db47; MSIP_Label_f42aa342-8706-4288-bd11-ebb85995028c_SetDate=2020-09-10T23:33:38.224Z; MSIP_Label_f42aa342-8706-4288-bd11-ebb85995028c_Name=General; MSIP_Label_f42aa342-8706-4288-bd11-ebb85995028c_ContentBits=0; MSIP_Label_f42aa342-8706-4288-bd11-ebb85995028c_Method=Standard;
authentication-results: dmarc.ietf.org; dkim=none (message not signed) header.d=none;dmarc.ietf.org; dmarc=none action=none header.from=cisco.com;
x-originating-ip: [2601:188:c400:bde0:3dc2:3183:59c8:3854]
x-ms-publictraffictype: Email
x-ms-office365-filtering-correlation-id: efa00be2-8b75-4ea2-4248-08d855ebcd4c
x-ms-traffictypediagnostic: BL0PR11MB3217:
x-microsoft-antispam-prvs: <BL0PR11MB3217690A0C200F25ABFD4F0AD8240@BL0PR11MB3217.namprd11.prod.outlook.com>
x-ms-oob-tlc-oobclassifiers: OLM:9508;
x-ms-exchange-senderadcheck: 1
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: 08oKSHwNwV3B3A+R7YeudH5SnUyeu+hGSPBAAyuK2eZsAIRCKVjnX77DCFfukpEquQ05etwo8lXdc248ymnc8iibWqfxrGlWdt0TSjQbahaQh1fteO0k07r4uFpW1DItVAwWWyUpcndbXiFVyHmjKsHHtbHJo4uq67dM20LIPLr1PhilkY78EiGeMyKb9zPSowHS3pp0MMmUS0WGplnR1rvkkNyp0eEfg30z0iHkDIVPbbbYeuM0R179A8Mfqw71zsL4yu6SxUITSEfYoJeqYj3Jj+zGGrQMhyDAba0mrHTf5s9770CkLepwrm33bIn9PVv41Pm/YRKKDtrsIdDhpwHzzPItwzzg1WanTVFYLFgty6BU/OlQ0PsSI21TNAIs6XyUOj1sJhTm5zTo6KGPkQ==
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:MN2PR11MB4760.namprd11.prod.outlook.com; PTR:; CAT:NONE; SFS:(396003)(136003)(346002)(366004)(376002)(39860400002)(52536014)(33656002)(5660300002)(7696005)(186003)(53546011)(478600001)(6506007)(316002)(45080400002)(8936002)(66556008)(66574015)(99936003)(166002)(110136005)(54906003)(4326008)(66446008)(64756008)(66476007)(71200400001)(966005)(66616009)(8676002)(86362001)(55016002)(66946007)(9686003)(2906002)(76116006); DIR:OUT; SFP:1101;
x-ms-exchange-antispam-messagedata: NPqXHHwvFHqrCi+iXs0h0khMjQtO17w+tvkCCR32NFU+5r0JZ/m1wLMpwxMrC0QO9Lhy7/TpvrSOm9qhDgyQaT+OlPIB8qSS+czk5qffMTRrHEM28lDD0dLrjNXml5auJdQ2Jk3VkNXEfj76pnAmNGowzoLBH+ru8djm4KgoveWy8C16uuVtcpMCkrcQS/gsZZuLfcECejsP7r89izOIgq/Y8OEnz6U8WXfFpb2lWqIzcq2NMsMHnbP81MlKOdpI/aEom+A2Mc2Qw906JDCsBAC40fDvF/sXY1L6IUL1rXOjyiOwvqwwdpo1eg0R1vozi1+4aHoYYeg5RuLFjqxXSAA8698eNWGiPcvkBt+9t7qbMnsRXXVa4GObj4QTo5iH0LwCvuE9xv/XW7qj2tlkrAjFGlSc9veULDL3nhiiT95VAc4EJ1kDEaxrWrg+hV9PwewPHhsxf6EAV6qkWc6w4gjNfMyjmw27F0IZLdBuap8FNpNwGbSy6V2FBRVEwk5l/CtCt25K151czMLCEQARjmFT0g1x3qaczvF8AFIYjR3UFs4RSIssiP2CXA17393YYsvMH+gOMFZiDVxI+BgxRrwMkMKhaumufRQ2QQm9gHKY8JOohwaAj6QDvbWQJ1oCK7/4o0vfyO5jIX3KUNketxe32izIUKmJAvZhefv5qk4E3LfHkWB3dqTOvdfqak/NuF+hOqnxqtCIjHv7xxPCCw==
x-ms-exchange-transport-forked: True
Content-Type: multipart/signed; protocol="application/x-pkcs7-signature"; micalg="SHA1"; boundary="----=_NextPart_000_0005_01D687B3.21230FD0"
MIME-Version: 1.0
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: MN2PR11MB4760.namprd11.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: efa00be2-8b75-4ea2-4248-08d855ebcd4c
X-MS-Exchange-CrossTenant-originalarrivaltime: 11 Sep 2020 00:44:12.1513 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 5ae1af62-9505-4097-a69a-c1553ef7840e
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: 5bHJOFvWGSEwX/QI8K15NUjiStP/vobV+QNkp4WG19PvsZ/tbsjBd3vbE++iz9bQiLJ256RtNdtX60huPYKoQA==
X-MS-Exchange-Transport-CrossTenantHeadersStamped: BL0PR11MB3217
X-OriginatorOrg: cisco.com
X-Outbound-SMTP-Client: 173.37.102.15, xch-rcd-005.cisco.com
X-Outbound-Node: rcdn-core-7.cisco.com
Archived-At: <https://mailarchive.ietf.org/arch/msg/add/CZVHjO1SVqMNO9hS50BjpHmLjgs>
Subject: Re: [Add] Zone ownership in DNS server discovery
X-BeenThere: add@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Applications Doing DNS <add.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/add>, <mailto:add-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/add/>
List-Post: <mailto:add@ietf.org>
List-Help: <mailto:add-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/add>, <mailto:add-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 11 Sep 2020 00:44:20 -0000

Thanks for the clarification.

I concur that this divergent behavior exists today with classic DNS.  Look
no further than TTL caching behavior of Outlook or Browsers.

 

I don't view this as a good thing but clearly understand the guidance being
given below.

 

-Vinny

 

From: Add <add-bounces@ietf.org> On Behalf Of Tommy Jensen
Sent: Thursday, September 10, 2020 7:34 PM
To: Vinny Parla (vparla) <vparla=40cisco.com@dmarc.ietf.org>
Cc: Jim Reid <jim@rfc1035.com>; ADD Mailing list <add@ietf.org>
Subject: Re: [Add] Zone ownership in DNS server discovery

 

Hey Vinny,

 

Yes, but I'd say that's not a hypothetical statement and is already true
today. A DNS client could implement a full recursive if they wanted to for
example and cache authoritative servers they discover, an extreme example of
"bypassing" a need for a recursive. 

 

I'm just suggesting the decision of what server to query for a given name is
up to individual implementors, and domains providing authoritative
information about designated DNS servers would make that easier than having
to be a full recursive (since you can slowly bootstrap these designations).

 

Thanks,

Tommy

================================================

The latest in Windows Internet Protocols:

  Native gRPC support:  <https://aka.ms/grpcblogpost>
https://aka.ms/grpcblogpost 

  DNS over HTTPS:  <https://aka.ms/dohblogpost> https://aka.ms/dohblogpost 

 

 

  _____  

From: Vinny Parla (vparla)
Sent: Thursday, September 10, 2020 4:18 PM
To: Tommy Jensen
Cc: ADD Mailing list; Jim Reid
Subject: [EXTERNAL] RE: Zone ownership in DNS server discovery 

 

Hi,

 

So if I understand the statement below, it is entirely up to an algorithm of
the implementor, which could differ from endpoint to endpoint or browser to
browse, to choose either to use the authoritative vs the recursive resolver.

 

Did I understand this correctly?

 

Thanks,

 

-Vinny