Re: [dnsext] Some thoughts on the updated aliasing draft

Tony Finch <dot@dotat.at> Mon, 28 March 2011 12:50 UTC

Return-Path: <fanf2@hermes.cam.ac.uk>
X-Original-To: dnsext@core3.amsl.com
Delivered-To: dnsext@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id 6B1333A68EA for <dnsext@core3.amsl.com>; Mon, 28 Mar 2011 05:50:31 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -6.361
X-Spam-Level:
X-Spam-Status: No, score=-6.361 tagged_above=-999 required=5 tests=[AWL=-0.062, BAYES_00=-2.599, RCVD_IN_DNSWL_MED=-4, SARE_WEOFFER=0.3]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id yVfHT8xJu4Yb for <dnsext@core3.amsl.com>; Mon, 28 Mar 2011 05:50:26 -0700 (PDT)
Received: from ppsw-50.csi.cam.ac.uk (ppsw-50.csi.cam.ac.uk [131.111.8.150]) by core3.amsl.com (Postfix) with ESMTP id 45D5F3A6817 for <dnsext@ietf.org>; Mon, 28 Mar 2011 05:50:26 -0700 (PDT)
X-Cam-AntiVirus: no malware found
X-Cam-SpamDetails: not scanned
X-Cam-ScannerInfo: http://www.cam.ac.uk/cs/email/scanner/
Received: from hermes-1.csi.cam.ac.uk ([131.111.8.51]:33350) by ppsw-50.csi.cam.ac.uk (smtp.hermes.cam.ac.uk [131.111.8.157]:25) with esmtpa (EXTERNAL:fanf2) id 1Q4BvO-0001xI-qk (Exim 4.72) (return-path <fanf2@hermes.cam.ac.uk>); Mon, 28 Mar 2011 13:52:02 +0100
Received: from fanf2 (helo=localhost) by hermes-1.csi.cam.ac.uk (hermes.cam.ac.uk) with local-esmtp id 1Q4BvO-0005yR-Az (Exim 4.67) (return-path <fanf2@hermes.cam.ac.uk>); Mon, 28 Mar 2011 13:52:02 +0100
Date: Mon, 28 Mar 2011 13:52:02 +0100
From: Tony Finch <dot@dotat.at>
X-X-Sender: fanf2@hermes-1.csi.cam.ac.uk
To: John Levine <johnl@iecc.com>
In-Reply-To: <20110327223114.95877.qmail@joyce.lan>
Message-ID: <alpine.LSU.2.00.1103281340430.3124@hermes-1.csi.cam.ac.uk>
References: <20110327223114.95877.qmail@joyce.lan>
User-Agent: Alpine 2.00 (LSU 1167 2008-08-23)
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset="US-ASCII"
Sender: Tony Finch <fanf2@hermes.cam.ac.uk>
Cc: dnsext@ietf.org
Subject: Re: [dnsext] Some thoughts on the updated aliasing draft
X-BeenThere: dnsext@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: DNS Extensions working group discussion list <dnsext.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/dnsext>, <mailto:dnsext-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/dnsext>
List-Post: <mailto:dnsext@ietf.org>
List-Help: <mailto:dnsext-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dnsext>, <mailto:dnsext-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 28 Mar 2011 12:50:31 -0000

John Levine <johnl@iecc.com> wrote:
>
> So what can we offer?  If it's something like CLONE or BNAME, we offer
> an upgrade path.  You're no worse off than you'd be with manual
> bundling and manual application configuration, and to the extent you
> upgrade your applications to know about the new DNS stuff, your
> configuration job gets easier.
>
> That's not as cool as the mythical magic hack.  Will people find it
> useful?  Having done my share of SMTP server hackery, I would.  If
> it's as important to handle variant names as people say it is, they'll
> upgrade.  If not, well, that's OK too.

Yes.

I think it's worth splitting the feature into forward and reverse parts.

The forward direction is alias -> canonical, as in CNAME and DNAME. We can
use CNAME synthesis to support old clients, and perhaps a DNSSEC algorithm
bump to avoid validator problems. Old servers can work with the new BNAME
(or whatever) aliases using their existing support for aliases, which
typically means explicit per-alias configuration.

The reverse direction is canonical name -> alias list, which is for the
server to automatically configure its aliases from a trusted part of the
DNS. (Does the client have any use for this information?) Servers that
understand this feature are easier to configure. This feature is also
useful if the aliases no not use BNAME, e.g. if they are CNAMEs or A or
AAAA records.

Both the new forward and reverse features will be useful independently of
each other.

Tony.
-- 
f.anthony.n.finch  <dot@dotat.at>  http://dotat.at/
Trafalgar: Westerly or southwesterly, becoming cyclonic at times, 4 or 5,
occasionally 6 in Biscay and Fitzroy. Moderate or rough. Rain or showers, fog
patches in north Biscay. Good to poor, occasionally very poor in north Biscay.