Re: [dane] Meeting in Hawaii?

Carsten Strotmann <carsten@strotmann.de> Mon, 06 October 2014 14:01 UTC

Return-Path: <carsten@strotmann.de>
X-Original-To: dane@ietfa.amsl.com
Delivered-To: dane@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 169B21A6F92 for <dane@ietfa.amsl.com>; Mon, 6 Oct 2014 07:01:38 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: 0.209
X-Spam-Level:
X-Spam-Status: No, score=0.209 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HELO_EQ_DE=0.35, HELO_MISMATCH_DE=1.448, HOST_MISMATCH_NET=0.311] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 0TOkVEmHmYfy for <dane@ietfa.amsl.com>; Mon, 6 Oct 2014 07:01:36 -0700 (PDT)
Received: from csgate3.strotmann.de (cstrotm-1-pt.tunnel.tserv5.lon1.ipv6.he.net [IPv6:2001:470:1f08:f1d::2]) (using TLSv1 with cipher ADH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 6F0251A6F9E for <dane@ietf.org>; Mon, 6 Oct 2014 07:00:56 -0700 (PDT)
Received: from csmobile4.home.strotmann.de (unknown [IPv6:2001:5c0:1400:a::839]) (using TLSv1 with cipher AES128-SHA (128/128 bits)) (No client certificate requested) by csgate3.strotmann.de (Postfix) with ESMTPSA id 98FF850ED; Mon, 6 Oct 2014 16:00:48 +0200 (CEST)
Date: Mon, 06 Oct 2014 16:00:50 +0200
From: Carsten Strotmann <carsten@strotmann.de>
To: Jens Wagner <jwagner@hexonet.net>
Message-ID: <20141006160050.2dc3cd2b@csmobile4.home.strotmann.de>
In-Reply-To: <5432514F.80403@hexonet.net>
References: <CAHw9_iLV1uWX2Fg5H9dBaMr=DsrGmyB_BJteP-kBA0MnXCkJ2w@mail.gmail.com> <E36D8CE6-F5E8-4606-950D-430FEAEA3523@kirei.se> <4C36FDC5-12D2-48C1-A3D5-7AA4090E98C8@isoc.org> <20141002233017.GQ13254@mournblade.imrryr.org> <21940.1412298125@sandelman.ca> <20141003021156.GR13254@mournblade.imrryr.org> <5431B1BE.2030008@hexonet.net> <20141006020540.GP13254@mournblade.imrryr.org> <5432514F.80403@hexonet.net>
X-Mailer: Claws Mail 3.10.1 (GTK+ 2.24.24; x86_64-redhat-linux-gnu)
MIME-Version: 1.0
Content-Type: text/plain; charset="US-ASCII"
Content-Transfer-Encoding: 7bit
Archived-At: http://mailarchive.ietf.org/arch/msg/dane/aZkAIo-3q74cTxCS7UI_5zdrtyc
Cc: dane@ietf.org
Subject: Re: [dane] Meeting in Hawaii?
X-BeenThere: dane@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: DNS-based Authentication of Named Entities <dane.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dane>, <mailto:dane-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/dane/>
List-Post: <mailto:dane@ietf.org>
List-Help: <mailto:dane-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dane>, <mailto:dane-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 06 Oct 2014 14:01:38 -0000

Hello Jens,

Jens Wagner writes:

>
> Basically, we are looking for nameservers, that:
>
> 1. allow you to add, remove and update zones online, anytime
> 2. do not 'stutter' or even stop resolving while getting updated, no 
> matter if single records are updated, or new zones added
> 3. do not need to keep all zones and records in memory
> 4. support DNSSEC + NSEC3
> 5. use internal caching for performance reasons


NSD, BIND9 and Knot should all satisfy the above, except for 3. YADIFA
might also, but I have no experience with it so far.

Is memory really an issue these days?

Microsoft WinDNS 2012R2 satisfies all points above, but has other
issues (no support for TLSA-RRs).

>
> PowerDNS provides all of the above, BIND9+DLZ does everything but 5., 
> MyDNS does everything but 4. (and is outdated).
> Most servers that are written for TLDs fail at 2. and or 3. Do you
> know any other products? Still hope for BIND10/Bundy.

Bundy-DNS would be an alternative satisfying all your requirements, but
it might not be "polished" enough in its current state. Bundy-DNS today
does not have full-time developers, no sponsor and is moving
slow. Please contact me off-list if you (or anyone) is interested to
testdrive Bundy-DNS or change the situation for the Bundy-DNS project.

--
Carsten Strotmann 
Email: cas@strotmann.de 
Blog:strotmann.de