Re: [dnsext] Re: EDNS client IP should be opt-in (Was: I-D ACTION:draft-vandergaast-edns-client-ip-00.txt

Wilmer van der Gaast <wilmer@google.com> Tue, 02 February 2010 21:58 UTC

Return-Path: <owner-namedroppers@ops.ietf.org>
X-Original-To: ietfarch-dnsext-archive@core3.amsl.com
Delivered-To: ietfarch-dnsext-archive@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id 68E453A69B8; Tue, 2 Feb 2010 13:58:35 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -102.558
X-Spam-Level:
X-Spam-Status: No, score=-102.558 tagged_above=-999 required=5 tests=[AWL=-2.685, BAYES_00=-2.599, FH_RELAY_NODNS=1.451, FM_FORGED_GMAIL=0.622, HELO_MISMATCH_COM=0.553, RDNS_NONE=0.1, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Xox2ud6KNkGL; Tue, 2 Feb 2010 13:58:34 -0800 (PST)
Received: from psg.com (psg.com [IPv6:2001:418:1::62]) by core3.amsl.com (Postfix) with ESMTP id 85ACD3A6985; Tue, 2 Feb 2010 13:58:34 -0800 (PST)
Received: from majordom by psg.com with local (Exim 4.71 (FreeBSD)) (envelope-from <owner-namedroppers@ops.ietf.org>) id 1NcQj5-000L6B-4a for namedroppers-data0@psg.com; Tue, 02 Feb 2010 21:56:03 +0000
Received: from [216.239.44.51] (helo=smtp-out.google.com) by psg.com with esmtps (TLSv1:AES256-SHA:256) (Exim 4.71 (FreeBSD)) (envelope-from <wilmer@google.com>) id 1NcQj2-000L5X-VT for namedroppers@ops.ietf.org; Tue, 02 Feb 2010 21:56:01 +0000
Received: from wpaz1.hot.corp.google.com (wpaz1.hot.corp.google.com [172.24.198.65]) by smtp-out.google.com with ESMTP id o12Lu08Y010486 for <namedroppers@ops.ietf.org>; Tue, 2 Feb 2010 13:56:00 -0800
DKIM-Signature: v=1; a=rsa-sha1; c=relaxed/relaxed; d=google.com; s=beta; t=1265147760; bh=HNPTGwElQMrxIQu/q0rJ0/wnxus=; h=MIME-Version:In-Reply-To:References:Date:Message-ID:Subject:From: To:Cc:Content-Type:Content-Transfer-Encoding; b=jBgCr6OAgjoUAERfTaYzuQvGdsqKtJQYpGcGSTZH/xhp+NKAI/Kbe6dEjzSuoGNtX bFJ2DXq04MK37gMJ40MUg==
DomainKey-Signature: a=rsa-sha1; s=beta; d=google.com; c=nofws; q=dns; h=mime-version:in-reply-to:references:date:message-id:subject:from:to: cc:content-type:content-transfer-encoding:x-system-of-record; b=HIfgXbOUSidAXD3Rz3U+hQYAbsmRe80Vvf/t2dQHJvU0VFmGqBp7yrnN3Pip0rrLG 55zGg+PZGZ9bEP5FRBjEA==
Received: from bwz8 (bwz8.prod.google.com [10.188.26.8]) by wpaz1.hot.corp.google.com with ESMTP id o12LtTc7017428 for <namedroppers@ops.ietf.org>; Tue, 2 Feb 2010 13:55:59 -0800
Received: by bwz8 with SMTP id 8so604795bwz.38 for <namedroppers@ops.ietf.org>; Tue, 02 Feb 2010 13:55:58 -0800 (PST)
MIME-Version: 1.0
Received: by 10.204.10.146 with SMTP id p18mr847543bkp.94.1265147758623; Tue, 02 Feb 2010 13:55:58 -0800 (PST)
In-Reply-To: <4B689CB8.9030702@isc.org>
References: <7c31c8cc1001271556w4918093er6e94e07cb92c4dc4@mail.gmail.com> <4B66E441.6090104@nic.cz> <4966825a1002010729m32b5ccfel94f7cb09d8b5e458@mail.gmail.com> <20100202113421.GA31244@nic.fr> <4966825a1002020355s41a182edvbc2fc8045af4a36e@mail.gmail.com> <4B681EB5.9040403@nic.cz> <71552.1265143879@nsa.vix.com> <7c31c8cc1002021327l4397502bk647f96813ac37948@mail.gmail.com> <4B689CB8.9030702@isc.org>
Date: Tue, 02 Feb 2010 21:55:58 +0000
Message-ID: <7c31c8cc1002021355p6e00eaeeq98b447466549e4ad@mail.gmail.com>
Subject: Re: [dnsext] Re: EDNS client IP should be opt-in (Was: I-D ACTION:draft-vandergaast-edns-client-ip-00.txt
From: Wilmer van der Gaast <wilmer@google.com>
To: Michael Graff <mgraff@isc.org>
Cc: DNSEXT WG <namedroppers@ops.ietf.org>
Content-Type: text/plain; charset="ISO-8859-1"
Content-Transfer-Encoding: quoted-printable
X-System-Of-Record: true
Sender: owner-namedroppers@ops.ietf.org
Precedence: bulk
List-ID: <namedroppers.ops.ietf.org>
List-Unsubscribe: To unsubscribe send a message to namedroppers-request@ops.ietf.org with
List-Unsubscribe: the word 'unsubscribe' in a single line as the message text body.
List-Archive: <http://ops.ietf.org/lists/namedroppers/>

On 2 February 2010 21:44, Michael Graff <mgraff@isc.org> wrote:
>> Note that this is already recommended in the first bullet point in
>> 8.2. Indeed we didn't ever intend this to be an "enabled by default"
>> feature.
>
> Then how can this possibly be useful?  This sort of optimization
> requires it to be performed for a large chunk of the users on the net,
> certainly for large ISPs and wireless providers.  While the number of
> servers may indeed be small, the number of clients benefiting from this
> (and therefore using it with or without their knowledge) has to be large.
>
Only clients of open resolvers and customers of ISPs with more peering
points than resolvers will benefit from this. Everybody else can
completely ignore this extension.

So it seems logical to not turn it on by default, also because it puts
significant pressure on caches and generates more load. *If* anyone
would turn it on by default, it'd better be mentioned in capitals in
the release notes.


Wilmer.

-- 
Wilmer van der Gaast, Dublin Traffic SRE.
Google Ireland.