Re: [BEHAVE] DNSsec in IPv6-only-hosts & discarding mapped AAAAs in DNS64

Rémi Després <remi.despres@free.fr> Fri, 08 May 2009 05:56 UTC

Return-Path: <remi.despres@free.fr>
X-Original-To: behave@core3.amsl.com
Delivered-To: behave@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id 2654E3A6ADC for <behave@core3.amsl.com>; Thu, 7 May 2009 22:56:44 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.674
X-Spam-Level:
X-Spam-Status: No, score=-1.674 tagged_above=-999 required=5 tests=[AWL=0.275, BAYES_00=-2.599, HELO_EQ_FR=0.35, MIME_8BIT_HEADER=0.3]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 7etll1Fctr+n for <behave@core3.amsl.com>; Thu, 7 May 2009 22:56:43 -0700 (PDT)
Received: from smtp3-g21.free.fr (smtp3-g21.free.fr [212.27.42.3]) by core3.amsl.com (Postfix) with ESMTP id 716FF3A68B1 for <behave@ietf.org>; Thu, 7 May 2009 22:56:39 -0700 (PDT)
Received: from smtp3-g21.free.fr (localhost [127.0.0.1]) by smtp3-g21.free.fr (Postfix) with ESMTP id E2CDE818049; Fri, 8 May 2009 07:58:04 +0200 (CEST)
Received: from RD-Mac.local (per92-10-88-166-221-144.fbx.proxad.net [88.166.221.144]) by smtp3-g21.free.fr (Postfix) with ESMTP id C19F08180FE; Fri, 8 May 2009 07:58:01 +0200 (CEST)
Message-ID: <4A03C9E6.2010905@free.fr>
Date: Fri, 08 May 2009 07:57:58 +0200
From: Rémi Després <remi.despres@free.fr>
User-Agent: Thunderbird 2.0.0.21 (Macintosh/20090302)
MIME-Version: 1.0
To: Dan Wing <dwing@cisco.com>
References: <4A02B8B9.1000905@free.fr> <004701c9cf50$9e3f1f40$c5f0200a@cisco.com>
In-Reply-To: <004701c9cf50$9e3f1f40$c5f0200a@cisco.com>
Content-Type: text/plain; charset="ISO-8859-15"; format="flowed"
Content-Transfer-Encoding: 7bit
Cc: 'Behave WG' <behave@ietf.org>
Subject: Re: [BEHAVE] DNSsec in IPv6-only-hosts & discarding mapped AAAAs in DNS64
X-BeenThere: behave@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: mailing list of BEHAVE IETF WG <behave.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/behave>, <mailto:behave-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/behave>
List-Post: <mailto:behave@ietf.org>
List-Help: <mailto:behave-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/behave>, <mailto:behave-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 08 May 2009 05:56:44 -0000

Dan Wing  -  le (m/j/a) 5/7/09 10:15 PM:

>> DNS64s:
>> -  as long as dual-stack hosts cannot be expected to act as
>> specified above, MUST discard mapped address records;
> 
> We would like dual-stack hosts to prefer native connectivity (rather 
> than translated connectivity).
> 
>> - after that, SHOULD forward them, at least if they are DNSsec
>> signed.
>> 
>> IPv6-only applications should not artificially block mapped
>> addresses destinations.
> 
> So applications and host OSs should ignore 
> draft-itojun-v6ops-v4mapped-harmful, correct?

Yes.
(Concerns of this draft don't apply in this case.)

> And I see how this could work now.

:-).

RD