Re: [dnsext] zone cut semantics

Michael Graff <mgraff@isc.org> Mon, 21 February 2011 16:55 UTC

Return-Path: <mgraff@isc.org>
X-Original-To: dnsext@core3.amsl.com
Delivered-To: dnsext@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id AC0663A7135 for <dnsext@core3.amsl.com>; Mon, 21 Feb 2011 08:55:12 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.599
X-Spam-Level:
X-Spam-Status: No, score=-2.599 tagged_above=-999 required=5 tests=[BAYES_00=-2.599]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 6pklj-qudABt for <dnsext@core3.amsl.com>; Mon, 21 Feb 2011 08:55:11 -0800 (PST)
Received: from mx.ams1.isc.org (mx.ams1.isc.org [IPv6:2001:500:60::65]) by core3.amsl.com (Postfix) with ESMTP id 642943A6DC6 for <dnsext@ietf.org>; Mon, 21 Feb 2011 08:55:07 -0800 (PST)
Received: from bikeshed.isc.org (bikeshed.isc.org [IPv6:2001:4f8:3:d::19]) (using TLSv1 with cipher DHE-RSA-CAMELLIA256-SHA (256/256 bits)) (Client CN "bikeshed.isc.org", Issuer "ISC CA" (verified OK)) by mx.ams1.isc.org (Postfix) with ESMTPS id 802005F98F3 for <dnsext@ietf.org>; Mon, 21 Feb 2011 16:55:35 +0000 (UTC) (envelope-from mgraff@isc.org)
Received: from WhiteDragon.local (173-27-162-196.client.mchsi.com [173.27.162.196]) (using TLSv1 with cipher DHE-RSA-CAMELLIA256-SHA (256/256 bits)) (Client did not present a certificate) by bikeshed.isc.org (Postfix) with ESMTPSA id 33AA1216C31 for <dnsext@ietf.org>; Mon, 21 Feb 2011 16:55:32 +0000 (UTC) (envelope-from mgraff@isc.org)
Message-ID: <4D629903.1020605@isc.org>
Date: Mon, 21 Feb 2011 10:55:31 -0600
From: Michael Graff <mgraff@isc.org>
User-Agent: Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10.6; en-US; rv:1.9.2.13) Gecko/20101207 Thunderbird/3.1.7
MIME-Version: 1.0
To: dnsext@ietf.org
References: <20110219210716.72943A5602B@drugs.dv.isc.org> <11263.1298150425@nsa.vix.com> <20110220072916.GA3505@vacation.karoshi.com.> <30899A4A-833B-42EF-9850-AFEE8B8DBE02@dotat.at> <AANLkTimNujeo6KiJ4wqUU-b3qyjozVmDvR8M3XNsfmKx@mail.gmail.com> <EBAC7E2F-FE70-497E-9C6C-DE4D2180CF7F@rfc1035.com>
In-Reply-To: <EBAC7E2F-FE70-497E-9C6C-DE4D2180CF7F@rfc1035.com>
X-Enigmail-Version: 1.1.1
Content-Type: text/plain; charset="ISO-8859-1"
Content-Transfer-Encoding: 7bit
Subject: Re: [dnsext] zone cut semantics
X-BeenThere: dnsext@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: DNS Extensions working group discussion list <dnsext.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/dnsext>, <mailto:dnsext-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/dnsext>
List-Post: <mailto:dnsext@ietf.org>
List-Help: <mailto:dnsext-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dnsext>, <mailto:dnsext-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 21 Feb 2011 16:55:12 -0000

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On 2/20/11 2:44 PM, Jim Reid wrote:

> Please think again about what you posted. The inference of what you say
> is that the root servers are authoritative for everything. That's
> clearly not true.

Actually, I think he's right technically, but not operationally.  The
root could return an auth answer for www.example.com if it wanted to,
and AFAIK resolvers would and should believe it.

It's a matter of policy and current use that we don't do that in the root.

- --Michael
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.11 (Darwin)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org/

iQEcBAEBAgAGBQJNYpkCAAoJEDRzoY2A7tzbWGEH/iuQqTSbzclUjSGL1xKv0Ulo
uxHWQ7DrywTo3OT4CWbIMHlokIRtuX4qACcuG0LR3BSDuucgS57bYXNk961mjyPk
HVoRm+cQgnVz7peAXfRv38p5z3kmTFoup+9T3L8xyIX3sL7KkJR4xRkqfcMH9gie
di61qZDqQ3QLm72qkanAuIPt+PKV3zRx1ny18Px3znvuU79P3TqoqsliesJg0W+v
znFuauOmfy4h05s/Jpbu60CUb1yifr2UFNd7E87yP6iLfH3B45JwXPLOzFVvO/7S
eC0GBT9eBMsKkKMacQlwnebYhxUTUFa+kkMvuAVuZDKXQhtSfheGTDOIBB4zvps=
=EYI8
-----END PGP SIGNATURE-----