Re: [dnsext] enough is enough

Stephane Bortzmeyer <bortzmeyer@nic.fr> Mon, 22 December 2014 09:17 UTC

Return-Path: <bortzmeyer@nic.fr>
X-Original-To: dnsext@ietfa.amsl.com
Delivered-To: dnsext@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id DB7A51A8A3F for <dnsext@ietfa.amsl.com>; Mon, 22 Dec 2014 01:17:01 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: 1.14
X-Spam-Level: *
X-Spam-Status: No, score=1.14 tagged_above=-999 required=5 tests=[BAYES_50=0.8, HELO_EQ_FR=0.35, T_RP_MATCHES_RCVD=-0.01] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id eYYJhUEYsQK0 for <dnsext@ietfa.amsl.com>; Mon, 22 Dec 2014 01:17:00 -0800 (PST)
Received: from mx4.nic.fr (mx4.nic.fr [IPv6:2001:67c:2218:2::4:12]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 0EBB81A8A20 for <dnsext@ietf.org>; Mon, 22 Dec 2014 01:17:00 -0800 (PST)
Received: from mx4.nic.fr (localhost [127.0.0.1]) by mx4.nic.fr (Postfix) with SMTP id 1C1C12803B1 for <dnsext@ietf.org>; Mon, 22 Dec 2014 10:16:58 +0100 (CET)
Received: from relay2.nic.fr (relay2.nic.fr [192.134.4.163]) by mx4.nic.fr (Postfix) with ESMTP id 185542802E1 for <dnsext@ietf.org>; Mon, 22 Dec 2014 10:16:58 +0100 (CET)
Received: from bortzmeyer.nic.fr (unknown [IPv6:2001:67c:1348:7::86:133]) by relay2.nic.fr (Postfix) with ESMTP id 1681CB3803E for <dnsext@ietf.org>; Mon, 22 Dec 2014 10:16:28 +0100 (CET)
Date: Mon, 22 Dec 2014 10:16:28 +0100
From: Stephane Bortzmeyer <bortzmeyer@nic.fr>
To: DNSEXT Group Working <dnsext@ietf.org>
Message-ID: <20141222091627.GB17938@nic.fr>
References: <20141220125805.GB20765@xs.powerdns.com> <20141220142506.C7EA12630502@rock.dv.isc.org> <A78F8417-AEA2-42BF-A7D5-96FE99DCBBBE@rfc1035.com> <20141220204337.4F47026313BC@rock.dv.isc.org> <7A31183A-CC1E-4F0A-A2EA-848B10B60A2B@insensate.co.uk> <E732A2F7-E467-4940-8A66-726FC894B4B3@frobbit.se> <20141221094454.GC13389@xs.powerdns.com> <11AD7639-D2AA-41F4-ACA4-70190E449253@rfc1035.com>
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Disposition: inline
In-Reply-To: <11AD7639-D2AA-41F4-ACA4-70190E449253@rfc1035.com>
X-Operating-System: Debian GNU/Linux 8.0
X-Kernel: Linux 3.16.0-4-686-pae i686
Organization: NIC France
X-URL: http://www.nic.fr/
User-Agent: Mutt/1.5.23 (2014-03-12)
Archived-At: http://mailarchive.ietf.org/arch/msg/dnsext/5tmlPrxlh4NyZ14-05M-lVeLMxw
Subject: Re: [dnsext] enough is enough
X-BeenThere: dnsext@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: DNS Extensions working group discussion list <dnsext.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dnsext>, <mailto:dnsext-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/dnsext/>
List-Post: <mailto:dnsext@ietf.org>
List-Help: <mailto:dnsext-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dnsext>, <mailto:dnsext-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 22 Dec 2014 09:17:02 -0000

On Sun, Dec 21, 2014 at 10:18:19AM +0000,
 Jim Reid <jim@rfc1035.com> wrote 
 a message of 34 lines which said:

> However this is howling at the moon. For decades the DNS industry
> has been unable to get people to fix their lame delegations or get
> them to stop using BIND8 or to use software which does EDNS or...

An experience at AFNIC: between 1996 and 2012, we had a mandatory
pre-delegation (and also pre-registration, which was not a good idea)
technical test, implemented by the Zonecheck program.

During this period, we had a lot of angry customers, many insults
(ranging from "incompetent bastards" to "lazy civil servants"), many
calls upon the ghost of Postel ("you should accept what is obviously
broken") and our dose of french-bashing
<http://www.circleid.com/posts/afnic_dns_server_redelegation/>

Registrars complained, bloggers complained, industry analysts
complained. Nobody supported us, not even the people and organisation
who have their mouth full of big words like "security and
stability". And noone tried to imitate us...

Even if you are a non-profit organisation, you have to pay the bills
(and the employees) so in the end, the forces of the free market won.

Zonecheck mandatory testing was retired in december 2012
<http://www.afnic.fr/fr/l-afnic-en-bref/actualites/actualites-operationnelles/6473/showOperational/maintenance-arret-de-la-chaine-d-enregistrement-le-17-12-de-18h30-a-20h30-1.html>
(french only)