Re: [dnsext] need new flag bit in EDNS, "do me no favours" (DMNF)

Florian Weimer <fweimer@bfk.de> Tue, 26 October 2010 10:41 UTC

Return-Path: <owner-namedroppers@ops.ietf.org>
X-Original-To: ietfarch-dnsext-archive@core3.amsl.com
Delivered-To: ietfarch-dnsext-archive@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id E9DD13A693E; Tue, 26 Oct 2010 03:41:42 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -0.583
X-Spam-Level:
X-Spam-Status: No, score=-0.583 tagged_above=-999 required=5 tests=[AWL=1.666, BAYES_00=-2.599, HELO_EQ_DE=0.35]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id zYTg0pi3TBE2; Tue, 26 Oct 2010 03:41:42 -0700 (PDT)
Received: from psg.com (psg.com [IPv6:2001:418:1::62]) by core3.amsl.com (Postfix) with ESMTP id 1652F3A6938; Tue, 26 Oct 2010 03:41:42 -0700 (PDT)
Received: from majordom by psg.com with local (Exim 4.72 (FreeBSD)) (envelope-from <owner-namedroppers@ops.ietf.org>) id 1PAgxD-0004XJ-Pm for namedroppers-data0@psg.com; Tue, 26 Oct 2010 10:40:31 +0000
Received: from mx01.bfk.de ([193.227.124.2]) by psg.com with esmtps (TLSv1:AES256-SHA:256) (Exim 4.72 (FreeBSD)) (envelope-from <fweimer@bfk.de>) id 1PAgxB-0004Wt-6D for namedroppers@ops.ietf.org; Tue, 26 Oct 2010 10:40:29 +0000
Received: from mx00.int.bfk.de ([10.119.110.2]) by mx01.bfk.de with esmtps (TLS1.0:RSA_AES_256_CBC_SHA1:32) id 1PAgx4-0000on-Rj; Tue, 26 Oct 2010 10:40:22 +0000
Received: by bfk.de with local id 1PAgx4-0006Z6-Lc; Tue, 26 Oct 2010 10:40:22 +0000
To: Roy Arends <roy@nominet.org.uk>
Cc: David Conrad <drc@virtualized.org>, Paul Vixie <vixie@isc.org>, "namedroppers@ops.ietf.org" <namedroppers@ops.ietf.org>
Subject: Re: [dnsext] need new flag bit in EDNS, "do me no favours" (DMNF)
References: <C8EA91CD.83C1%roy@nominet.org.uk>
From: Florian Weimer <fweimer@bfk.de>
Date: Tue, 26 Oct 2010 10:40:22 +0000
In-Reply-To: <C8EA91CD.83C1%roy@nominet.org.uk> (Roy Arends's message of "Sun\, 24 Oct 2010 23\:45\:49 +0000")
Message-ID: <82eibdutih.fsf@mid.bfk.de>
MIME-Version: 1.0
Content-Type: text/plain; charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable
Sender: owner-namedroppers@ops.ietf.org
Precedence: bulk
List-ID: <namedroppers.ops.ietf.org>
List-Unsubscribe: To unsubscribe send a message to namedroppers-request@ops.ietf.org with
List-Unsubscribe: the word 'unsubscribe' in a single line as the message text body.
List-Archive: <http://ops.ietf.org/lists/namedroppers/>

* Roy Arends:

> On 10/25/10 1:24 AM, "David Conrad" <drc@virtualized.org> wrote:
>
>> On Oct 24, 2010, at 4:01 PM, Roy Arends wrote:
>> 
>>> The end-game will be applications doing their own resolving. Real control.
>>> No third party dependencies. No favors to ask.
>> 
>> And greatly reduced caching.
>
> Yes, and greatly reduced impact of a spoofed cache.

You can reduce caching of unstable records, to avoid the amplification
effect of a poisoned cache, too. 8-)

-- 
Florian Weimer                <fweimer@bfk.de>
BFK edv-consulting GmbH       http://www.bfk.de/
Kriegsstraße 100              tel: +49-721-96201-1
D-76133 Karlsruhe             fax: +49-721-96201-99