Re: RFC 2119 section 6

Brian Wellington <Brian.Wellington@nominum.com> Wed, 11 July 2001 07:46 UTC

Received: from psg.com (exim@psg.com [147.28.0.62]) by ietf.org (8.9.1a/8.9.1a) with SMTP id DAA27431 for <dnsext-archive@lists.ietf.org>; Wed, 11 Jul 2001 03:46:22 -0400 (EDT)
Received: from lserv by psg.com with local (Exim 3.31 #1) id 15KEJy-0003Ep-00 for namedroppers-data@psg.com; Wed, 11 Jul 2001 00:22:06 -0700
Received: from rip.psg.com ([147.28.0.39] ident=exim) by psg.com with esmtp (Exim 3.31 #1) id 15KEJx-0003Ed-00 for namedroppers@ops.ietf.org; Wed, 11 Jul 2001 00:22:05 -0700
Received: from randy by rip.psg.com with local (Exim 3.30 #1) id 15KEJx-000IjX-00 for namedroppers@ops.ietf.org; Wed, 11 Jul 2001 00:22:05 -0700
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
From: Brian Wellington <Brian.Wellington@nominum.com>
To: "D. J. Bernstein" <djb@cr.yp.to>
Cc: namedroppers@ops.ietf.org
Subject: Re: RFC 2119 section 6
In-Reply-To: <E15K8Yt-000IXm-00@psg.com>
Sender: owner-namedroppers@ops.ietf.org
Precedence: bulk
Message-Id: <E15KEJy-0003Ep-00@psg.com>
Date: Wed, 11 Jul 2001 00:22:06 -0700
Content-Transfer-Encoding: 7bit

On Tue, 10 Jul 2001, D. J. Bernstein wrote:

> Kevin Darcy writes:
> > TSIG and EDNS0 are already with us, and as far as I know it is legal
> > for either or both to be transmitted in an AXFR response
>
> Only by bilateral agreement.

A TKEY can spontaneously be added to a response.  See RFC 2930, section 5.
I don't think this is a good idea, but it is a spec.  It says

	This SHOULD only be done if the server
	knows the querier understands TKEY and has this option implemented

but that doesn't prevent a server from doing it in other cases.  It would
be completely legal for a server to implement this, and it would cause
your AXFR client to import a TKEY record into the zone.

> Terrified of new ports? Fine. Use a new EXFR query type. This is not
> rocket science.

Which, for every DNS implementation except yours, would be identical to
AXFR.

> > you have IMO fallen far short of demonstrating that
> > "section-agnosticism" has any practical value
>
> I have thousands of sites whose adminitsrators don't want to be forced
> to upgrade their working DNS software. If you don't think compatibility
> has ``practical value,'' you're an idiot.

No one's forcing users to do anything.  This is a fairly minor point, and
even if your client is non-compliant, it has virtually no interoperability
issues.  I wouldn't go out of my way to update sites that I administered
just because of this.

Brian



to unsubscribe send a message to namedroppers-request@ops.ietf.org with
the word 'unsubscribe' in a single line as the message text body.