Re: [Add] [EXTERNAL] Re: add-enterprise-split-dns and split horizon DNS

Michael Richardson <mcr+ietf@sandelman.ca> Fri, 03 December 2021 22:51 UTC

Return-Path: <mcr+ietf@sandelman.ca>
X-Original-To: add@ietfa.amsl.com
Delivered-To: add@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 3ADCC3A0AD5 for <add@ietfa.amsl.com>; Fri, 3 Dec 2021 14:51:59 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.099
X-Spam-Level:
X-Spam-Status: No, score=-2.099 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=sandelman.ca
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id eiQmSElaHwot for <add@ietfa.amsl.com>; Fri, 3 Dec 2021 14:51:54 -0800 (PST)
Received: from tuna.sandelman.ca (tuna.sandelman.ca [IPv6:2607:f0b0:f:3:216:3eff:fe7c:d1f3]) (using TLSv1.2 with cipher ADH-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 85C733A0AD3 for <add@ietf.org>; Fri, 3 Dec 2021 14:51:54 -0800 (PST)
Received: from localhost (localhost [127.0.0.1]) by tuna.sandelman.ca (Postfix) with ESMTP id 539B638ADC; Fri, 3 Dec 2021 17:55:18 -0500 (EST)
Received: from tuna.sandelman.ca ([127.0.0.1]) by localhost (localhost [127.0.0.1]) (amavisd-new, port 10024) with LMTP id jkEV6efXVsVc; Fri, 3 Dec 2021 17:55:17 -0500 (EST)
Received: from sandelman.ca (obiwan.sandelman.ca [IPv6:2607:f0b0:f:2::247]) by tuna.sandelman.ca (Postfix) with ESMTP id 0B05938AAF; Fri, 3 Dec 2021 17:55:17 -0500 (EST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=sandelman.ca; s=mail; t=1638572117; bh=nZW2xXoCNEdeAVec+Z9dOC2/LeLHrH+gFIGB8kxazT0=; h=From:To:cc:Subject:In-Reply-To:References:Date:From; b=XfW/zWA6dx1rYDLC4PfZJ1FSCgzCuhmIjrE041FQvRhNWLLA0/mZoZGu1BTWx0YFl SwdTXz2S/J25jJl+rAli8f54BEWgRBFgOPdEq+1y9VBgGOeV+STUjdue+PxFejQkNn Muk2S/R7ATUI8JdPdlW1lKTh7ASUleA4+waPm7MlUd3/0ywOHXB4jk/u4daLkYH20J L/aVeo6Pzw87EdS555XOe84xlH14Viar/zihgQTvfSUCX6CUv1/hNKQXSKwjwDVa11 0kMucvguTGNGBQafqDQv28uDOFMRMgErUN4FdS9G22obTUxT94jj2NCFo6u4EjNlWl wSF5bargMPHAg==
Received: from localhost (localhost [IPv6:::1]) by sandelman.ca (Postfix) with ESMTP id 2A1967EA; Fri, 3 Dec 2021 17:51:50 -0500 (EST)
From: Michael Richardson <mcr+ietf@sandelman.ca>
To: "Deen, Glenn (NBCUniversal)" <Glenn.Deen@nbcuni.com>
cc: ADD Mailing list <add@ietf.org>
In-Reply-To: <C27FDD98-D80D-4DB8-83D7-3B1BB686F509@nbcuni.com>
References: <152347.1638473207@dooku> <CABcZeBMyZLSE2HZ2dL+P6Dq3hMaG2QgTRrUuAjHTB7pJpXTaMQ@mail.gmail.com> <8AF4482A-A656-4999-8127-39D94FC914AF@gmail.com> <C27FDD98-D80D-4DB8-83D7-3B1BB686F509@nbcuni.com>
X-Mailer: MH-E 8.6+git; nmh 1.7+dev; GNU Emacs 26.1
X-Face: $\n1pF)h^`}$H>Hk{L"x@)JS7<%Az}5RyS@k9X%29-lHB$Ti.V>2bi.~ehC0; <'$9xN5Ub# z!G,p`nR&p7Fz@^UXIn156S8.~^@MJ*mMsD7=QFeq%AL4m<nPbLgmtKK-5dC@#:k
MIME-Version: 1.0
Content-Type: multipart/signed; boundary="=-=-="; micalg="pgp-sha512"; protocol="application/pgp-signature"
Date: Fri, 03 Dec 2021 17:51:50 -0500
Message-ID: <16475.1638571910@localhost>
Archived-At: <https://mailarchive.ietf.org/arch/msg/add/zMnynyujFRL3VcThmG1pZsOdhi0>
Subject: Re: [Add] [EXTERNAL] Re: add-enterprise-split-dns and split horizon DNS
X-BeenThere: add@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Applications Doing DNS <add.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/add>, <mailto:add-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/add/>
List-Post: <mailto:add@ietf.org>
List-Help: <mailto:add-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/add>, <mailto:add-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 03 Dec 2021 22:51:59 -0000

Deen, Glenn (NBCUniversal) <Glenn.Deen@nbcuni.com> wrote:
    > DNSSEC & DANE adoption is a great topic, but needs more beverages than
    > available in a virtual environment.

    > Can we please focus on discovery issues as I fear this other topic set
    > has the potential to fill up everyone's inbox and still not resolve
    > anything.

Sorry, I can't abide by this.

This is germane to whether or not split-horizon-dns is really a problem that
needs solved. Is typo-squatting really a concern when there is split-horizon DNS?

I claim that it isn't: that DNSSEC provides for corp.example.com delegations
that satisfy all of the issues that multiple-views claims to solve.

If you agree with me, then don't adopt the document.
It you disagree with me, then DDR has to deal with all the shit that DNSSEC
was intended to solve.

--
Michael Richardson <mcr+IETF@sandelman.ca>   . o O ( IPv6 IøT consulting )
           Sandelman Software Works Inc, Ottawa and Worldwide