Re: [dnsext] need new flag bit in EDNS, "do me no favours" (DMNF)

Florian Weimer <fweimer@bfk.de> Tue, 26 October 2010 10:41 UTC

Return-Path: <owner-namedroppers@ops.ietf.org>
X-Original-To: ietfarch-dnsext-archive@core3.amsl.com
Delivered-To: ietfarch-dnsext-archive@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id 5D2413A6939; Tue, 26 Oct 2010 03:41:28 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -0.521
X-Spam-Level:
X-Spam-Status: No, score=-0.521 tagged_above=-999 required=5 tests=[AWL=1.728, BAYES_00=-2.599, HELO_EQ_DE=0.35]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 8vquf+aCf2EL; Tue, 26 Oct 2010 03:41:27 -0700 (PDT)
Received: from psg.com (psg.com [IPv6:2001:418:1::62]) by core3.amsl.com (Postfix) with ESMTP id 21BBB3A6941; Tue, 26 Oct 2010 03:41:27 -0700 (PDT)
Received: from majordom by psg.com with local (Exim 4.72 (FreeBSD)) (envelope-from <owner-namedroppers@ops.ietf.org>) id 1PAgw9-0004Qj-L6 for namedroppers-data0@psg.com; Tue, 26 Oct 2010 10:39:25 +0000
Received: from mx01.bfk.de ([193.227.124.2]) by psg.com with esmtps (TLSv1:AES256-SHA:256) (Exim 4.72 (FreeBSD)) (envelope-from <fweimer@bfk.de>) id 1PAgw6-0004QB-RB for namedroppers@ops.ietf.org; Tue, 26 Oct 2010 10:39:23 +0000
Received: from mx00.int.bfk.de ([10.119.110.2]) by mx01.bfk.de with esmtps (TLS1.0:RSA_AES_256_CBC_SHA1:32) id 1PAgw1-0000er-Mg; Tue, 26 Oct 2010 10:39:17 +0000
Received: by bfk.de with local id 1PAgw1-00055L-JZ; Tue, 26 Oct 2010 10:39:17 +0000
To: Paul Vixie <vixie@isc.org>
Cc: namedroppers@ops.ietf.org
Subject: Re: [dnsext] need new flag bit in EDNS, "do me no favours" (DMNF)
References: <59023.1287939121@nsa.vix.com>
From: Florian Weimer <fweimer@bfk.de>
Date: Tue, 26 Oct 2010 10:39:17 +0000
In-Reply-To: <59023.1287939121@nsa.vix.com> (Paul Vixie's message of "Sun\, 24 Oct 2010 16\:52\:01 +0000")
Message-ID: <82iq0putka.fsf@mid.bfk.de>
MIME-Version: 1.0
Content-Type: text/plain; charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable
Sender: owner-namedroppers@ops.ietf.org
Precedence: bulk
List-ID: <namedroppers.ops.ietf.org>
List-Unsubscribe: To unsubscribe send a message to namedroppers-request@ops.ietf.org with
List-Unsubscribe: the word 'unsubscribe' in a single line as the message text body.
List-Archive: <http://ops.ietf.org/lists/namedroppers/>

* Paul Vixie:

> i'm thinking we need a flag bit in edns to allow a client to opt out of
> things like "web error redirection" (dns ad insertion).  the semantics
> of it would just be, if server policy allows "clear path" dns for this
> query, then the server is requested to provide same.

Does EDNS actually work on the last mile?

What about expressing this in terms of the trust anchors you're
willing to accept?

-- 
Florian Weimer                <fweimer@bfk.de>
BFK edv-consulting GmbH       http://www.bfk.de/
Kriegsstraße 100              tel: +49-721-96201-1
D-76133 Karlsruhe             fax: +49-721-96201-99