[DNSOP] Re: Updates to Locally Served DNS Zones and IP Special-Purpose Address Space Registries

marka <marka@isc.org> Mon, 25 May 2026 01:04 UTC

Return-Path: <marka@isc.org>
X-Original-To: dnsop@mail2.ietf.org
Delivered-To: dnsop@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 537C6F461C28; Sun, 24 May 2026 18:04:57 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1779671097; bh=+n27/7LqHGMQaTav4XHXkWrVtJ6MhtQ/GaHoKWPjCVI=; h=Subject:From:In-Reply-To:Date:Cc:References:To; b=q28QHze/G/4RduYRldiEwTKSW3u2LX1sPN0DzHKQcgzaX3YGyitJrtzi9bjYoo7Tx fl4ucG5rzbwpqWbkAEER/LiH6AJcXhQ/pGbToiiRh9laenO4JD3yXdp+x6f16A6hGd 6AWza/qavOX5iPIWdyJt/II1EFXVTqgepab8VpRc=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -4.399
X-Spam-Level:
X-Spam-Status: No, score=-4.399 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_MED=-2.3, RCVD_IN_VALIDITY_CERTIFIED_BLOCKED=0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (1024-bit key) header.d=isc.org header.b="SUBNkYt3"; dkim=pass (1024-bit key) header.d=isc.org header.b="bJZYlVSE"
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id LNbBC-TDRHa6; Sun, 24 May 2026 18:04:56 -0700 (PDT)
Received: from mx.pao1.isc.org (mx.pao1.isc.org [149.20.2.50]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 84CD2F461C23; Sun, 24 May 2026 18:04:56 -0700 (PDT)
Received: from zimbra10.isc.org (zimbra10.isc.org [149.20.2.90]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (Client did not present a certificate) by mx.pao1.isc.org (Postfix) with ESMTPS id 861E04E408B; Mon, 25 May 2026 01:04:49 +0000 (UTC)
ARC-Filter: OpenARC Filter v1.0.0 mx.pao1.isc.org 861E04E408B
Authentication-Results: mx.pao1.isc.org; arc=none smtp.remote-ip=149.20.2.90
ARC-Seal: i=1; a=rsa-sha256; d=isc.org; s=ostpay; t=1779671089; cv=none; b=DQ9CoI4Y2JEKAmcFXfA1z36aTVDZ4gW+XZW1iJC6ti06V60cpzYqY/m5L5UoSUvWaDjybTRsKe4gqi9n3N42kuH9mFMgAbekJ2yImYZpaZNxTZV7wcL4jkcskgqU2exKazpLBxSlB5UHhyoTJsdweJrRrJUSs3uVEzh6h2vtIzU=
ARC-Message-Signature: i=1; a=rsa-sha256; d=isc.org; s=ostpay; t=1779671089; c=relaxed/relaxed; bh=NlsjXF15Yt0VhobXfFKhRmMpgWHVfIt9tL0o1cA+BKc=; h=DKIM-Signature:DKIM-Signature:Mime-Version:Subject:From:Date: Message-Id:To; b=eem5LKqS6AQ0NKoBQaOdzUiC5zXkVcvbUz58yPJmwNRSA7XqIhEJL9MN4C0s41RT9oASfiDX1HHl2f16JqXThVu8ng4k7APjrVrynJoA++/nFKy61hYypfSnmCwiXTiDNg2FHeHvstjIH8pv0DJguQjmKG5o0gQTFl4mrUqa/6c=
ARC-Authentication-Results: i=1; mx.pao1.isc.org
DKIM-Filter: OpenDKIM Filter v2.10.3 mx.pao1.isc.org 861E04E408B
DKIM-Signature: v=1; a=rsa-sha256; c=simple/simple; d=isc.org; s=ostpay; t=1779671089; bh=+n27/7LqHGMQaTav4XHXkWrVtJ6MhtQ/GaHoKWPjCVI=; h=Subject:From:In-Reply-To:Date:Cc:References:To; b=SUBNkYt3d7UML1Gpgwnow9e9I/SIgSbSzXzXglWocK7x1N9CjL7qg3OsxIFBI8r3c L8YpY3x1GruyfQvLod98OGRGpa1+pJje+4UVDOHdEnBXjnM6ct3pAO8YbvzQKoXGkU NOj+F8T1cqCNlYU2WEtXZ9k4vahE75W+2slyCUfw=
Received: from zimbra10.isc.org (localhost [127.0.0.1]) by zimbra10.isc.org (Postfix) with ESMTPS id 7D99C2E601D2; Mon, 25 May 2026 01:04:49 +0000 (UTC)
Received: from zimbra10.isc.org (localhost [127.0.0.1]) by zimbra10.isc.org (Postfix) with ESMTPS id 6EF602E601D4; Mon, 25 May 2026 01:04:49 +0000 (UTC)
DKIM-Filter: OpenDKIM Filter v2.10.3 zimbra10.isc.org 6EF602E601D4
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=isc.org; s=05DFB016-56A2-11EB-AEC0-15368D323330; t=1779671089; bh=NlsjXF15Yt0VhobXfFKhRmMpgWHVfIt9tL0o1cA+BKc=; h=Mime-Version:From:Date:Message-Id:To; b=bJZYlVSEVBT/PfQg/ewIqa8gKGOu8SvnY5mfczLgQNhB8Y2HIgVI3GD2cRO6CjXil v9ZfjFM17xHt5Ru73UBiaxOB68RPqeGtuQ78PUMtefqB8dGMsSEJzdCQHh8LjSgicl 2J6VF9fDVGWw+q11rM0PpsR0mzPDwhRbAiBJ1lDA=
Received: from smtpclient.apple (n49-187-18-238.bla1.nsw.optusnet.com.au [49.187.18.238]) by zimbra10.isc.org (Postfix) with ESMTPSA id 00A522E601D2; Mon, 25 May 2026 01:04:47 +0000 (UTC)
Content-Type: text/plain; charset="utf-8"
Mime-Version: 1.0 (Mac OS X Mail 16.0 \(3731.700.6.1.21\))
From: marka <marka@isc.org>
In-Reply-To: <PAUP264MB6756B7E27C2C9ED569926061880F2@PAUP264MB6756.FRAP264.PROD.OUTLOOK.COM>
Date: Mon, 25 May 2026 11:04:25 +1000
Content-Transfer-Encoding: quoted-printable
Message-Id: <A3015C2B-5B5E-4B81-815E-1B27F38EB0B9@isc.org>
References: <176470326775.3865625.13674433448581157459@dt-datatracker-5bd94c585b-wk4l4> <CADyWQ+Fxk-Op+5Lkrwj-b9MAevzAwNebs+7PwJS+DQLPCcUWFw@mail.gmail.com> <PAUP264MB6756EA9C248C08F5E5AB1E1188D9A@PAUP264MB6756.FRAP264.PROD.OUTLOOK.COM> <CADyWQ+F59eO0wMhsm6V9ka5UWSOfm+80GmJ5H-x-3zqDw-QoMQ@mail.gmail.com> <CACMsEX-wmeywa-yhEy-7N4rEWgOa2URAuHaAeSX8kEcrjgvFNA@mail.gmail.com> <PAUP264MB675631DA8CD71E8C745D0C0F883C2@PAUP264MB6756.FRAP264.PROD.OUTLOOK.COM> <CADyWQ+E+Y5ogHP0c2p8uNBNpHWetyQSaY_hc5iVXdy2nRTgizA@mail.gmail.com> <PAUP264MB6756B7E27C2C9ED569926061880F2@PAUP264MB6756.FRAP264.PROD.OUTLOOK.COM>
To: mohamed.boucadair@orange.com
X-Mailer: Apple Mail (2.3731.700.6.1.21)
Message-ID-Hash: CAU2S44Q3OBYBDFS63MBCSL745O4LXWH
X-Message-ID-Hash: CAU2S44Q3OBYBDFS63MBCSL745O4LXWH
X-MailFrom: marka@isc.org
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-dnsop.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: Tim Wicinski <tjw.ietf@gmail.com>, Nick Buraglio <buraglio@forwardingplane.net>, David Farmer <farmer@umn.edu>, list <v6ops@ietf.org>, 6MAN <6man@ietf.org>, dnsop WG <dnsop@ietf.org>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [DNSOP] Re: Updates to Locally Served DNS Zones and IP Special-Purpose Address Space Registries
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/dnsop/-Z6uEcNZS0O7dX1TAAx9MkS1c3A>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dnsop>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Owner: <mailto:dnsop-owner@ietf.org>
List-Post: <mailto:dnsop@ietf.org>
List-Subscribe: <mailto:dnsop-join@ietf.org>
List-Unsubscribe: <mailto:dnsop-leave@ietf.org>

fc00::/7 Unique-Local needs to be considered as two seperate entries as
the /8’s are subject to different allocation rules.  fc00::/8 is currently
reserved.  fd00::/8 is already listed as a Local Served zone, has been included
as a locally served zone for in DNS servers for years and IANA has
an insecure delegation back to the parent servers which creates a break
in the DNSSEC chain of trust.

Mark

> On 22 May 2026, at 18:49, mohamed.boucadair@orange.com wrote:
> 
> Hi Tim,
>  Thank you for the update.
>  For the IANA registrations, you may consider including tables such as:
>  
>     • Request updating IPv6 Special-Purpose Address Space as follows (PLEASE DOUBLE CHECK)
>  Address Block  Name  Eligible to Locally-Served DNS Zones::1/128 Loopback Address True
> ::/128 Unspecified Address True
> ::ffff:0:0/96 IPv4-mapped Address Flase
> 64:ff9b::/96 IPv4-IPv6 Translat. False
> 64:ff9b:1::/48 IPv4-IPv6 Translat. False
> 100::/64 Discard-Only Address Block False
> 100:0:0:1::/64 Dummy IPv6 Prefix False
> 2001::/23 IETF Protocol Assignments False
> 2001::/32 TEREDO False
> 2001:1::1/128 Port Control Protocol Anycast False
> 2001:1::2/128 Traversal Using Relays around NAT Anycast False
> 2001:1::3/128 DNS-SD Service Registration Protocol Anycast False
> 2001:2::/48 Benchmarking False
> 2001:3::/32 AMT False
> 2001:4:112::/48 AS112-v6 False
> 2001:10::/28 Deprecated (previously ORCHID)
> 2001:20::/28 ORCHIDv2 False
> 2001:30::/28 Drone Remote ID Protocol Entity Tags (DETs) Prefix False
> 2001:db8::/32 Documentation True
> 2002::/16 [3] 6to4 False
> 2620:4f:8000::/48 Direct Delegation AS112 Service False
> 3fff::/20 Documentation True
> 5f00::/16 Segment Routing (SRv6) SIDs False
> fc00::/7 Unique-Local False
> fe80::/10 Link-Local Unicast True
>  
>     • Request updating IPv4 Special-Purpose Address Space as follows (PLEASE DOUBLE CHECK)
>  Address Block  Name  Eligible to Locally-Served DNS Zones0.0.0.0/8 "This network" True
> 0.0.0.0/32 "This host on this network" True
> 10.0.0.0/8 Private-Use True
> 100.64.0.0/10 Shared Address Space False
> 127.0.0.0/8 Loopback True
> 169.254.0.0/16 Link Local True
> 172.16.0.0/12 Private-Use True
> 192.0.0.0/24 [2] IETF Protocol Assignments False
> 192.0.0.0/29 IPv4 Service Continuity Prefix False
> 192.0.0.8/32 IPv4 dummy address False
> 192.0.0.9/32 Port Control Protocol Anycast False
> 192.0.0.10/32 Traversal Using Relays around NAT Anycast False
> 192.0.0.170/32, 192.0.0.171/32 NAT64/DNS64 Discovery False
> 192.0.2.0/24 Documentation (TEST-NET-1) True
> 192.31.196.0/24 AS112-v4 False
> 192.52.193.0/24 AMT False
> 192.88.99.0/24 Deprecated (6to4 Relay Anycast)
> 192.88.99.2/32 6a44-relay anycast address False
> 192.168.0.0/16 Private-Use True
> 192.175.48.0/24 Direct Delegation AS112 Service False
> 198.18.0.0/15 Benchmarking False
> 198.51.100.0/24 Documentation (TEST-NET-2) True
> 203.0.113.0/24 Documentation (TEST-NET-3) True
> 240.0.0.0/4 Reserved False
> 255.255.255.255/32 Limited Broadcast True
>  Hope this helps.
>  Cheers,
> Med
>  De : Tim Wicinski <tjw.ietf@gmail.com> 
> Envoyé : jeudi 21 mai 2026 17:03
> À : BOUCADAIR Mohamed INNOV/NET <mohamed.boucadair@orange.com>
> Cc : Nick Buraglio <buraglio@forwardingplane.net>; David Farmer <farmer@umn.edu>; list <v6ops@ietf.org>; 6MAN <6man@ietf.org>; dnsop WG <dnsop@ietf.org>
> Objet : Re: Updates to Locally Served DNS Zones and IP Special-Purpose Address Space Registries
>   Med
>  Sorry I missed this - I pushed an update earlier this week with some changes to get all the references in there. 
> Next steps should be some reviews - there are a couple of sections on "Initial Registry" that I am not sure if we should point to what exists or duplicate them.  Operational Considerations I can work on
>  tim
>   On Thu, May 7, 2026 at 4:01 AM <mohamed.boucadair@orange.com> wrote:
> Hi Tim, all,
>  Thank you for publishing a new version: https://datatracker.ietf.org/doc/draft-dnsop-rfc6303-bis/01/. In your opinion, what would be the next step to make some progress here?
>  Adding 6man and DNSOP as this touches registries defined by these WGs.
>  Cheers,
> Med
>  De : Nick Buraglio <buraglio@forwardingplane.net> 
> Envoyé : mercredi 25 février 2026 17:25
> À : Tim Wicinski <tjw.ietf@gmail.com>
> Cc : BOUCADAIR Mohamed INNOV/NET <mohamed.boucadair@orange.com>; list <v6ops@ietf.org>
> Objet : Re: [v6ops] Re: Fwd: New Version Notification for draft-dnsop-rfc6303-bis-00.txt
>   Hi Tim. We were discussing this as part of the v6ops AD call prior to IETF 125 - is there any movement on this draft? What can we help with? 
>  nb
>  On Wed, Dec 3, 2025 at 12:48 PM Tim Wicinski <tjw.ietf@gmail.com> wrote:
> Med
>  Thanks for the suggestions ! I wanted to get something in place and I poked Mr Farmer hoping for his insights. 
>  And I realized after I published the version it's not a -bis also. 
>  I'll clean this up today/tomorrow. 
>  tim
>   On Wed, Dec 3, 2025 at 7:53 AM <mohamed.boucadair@orange.com> wrote:
> Hi Tim,
>  Thank you for editing the -00.
>  I think that the doc should also update RFC6890 per the discussion we had with David. The update to 6890 is about adding a new column to indicate whether an entry in the registry is eligible to being listed in locally served zones. The expert of the locally served zones registry will also have the responsibility to validate reverse entries that will be mirrored from the special registry.  Linking both registries will ensure consistency between the two, with the special address registry being the main entry point.
>  One minor nit, I suspect that the “-bis” in the file name may be misleading for some as this is not a bis, but an update.  Cheers,
> Med
>  De : Tim Wicinski <tjw.ietf@gmail.com> 
> Envoyé : mardi 2 décembre 2025 20:23
> À : list <v6ops@ietf.org>
> Objet : [v6ops] Fwd: New Version Notification for draft-dnsop-rfc6303-bis-00.txt
>    Hi
>  Per discussions with Med and Dave Farmer, I submitted a rough draft to sketch out the changes for 6303. 
> Need to work on the Guidance for Expert Reviewers, but wanted to make a start of things. 
>  Feedback Welcome!
>  tim
>  ---------- Forwarded message ---------
> From: <internet-drafts@ietf.org>
> Date: Tue, Dec 2, 2025 at 2:21 PM
> Subject: New Version Notification for draft-dnsop-rfc6303-bis-00.txt
> To: Tim Wicinski <tjw.ietf@gmail.com>
> 
> 
> A new version of Internet-Draft draft-dnsop-rfc6303-bis-00.txt has been
> successfully submitted by Tim Wicinski and posted to the
> IETF repository.
> 
> Name:     draft-dnsop-rfc6303-bis
> Revision: 00
> Title:    Revision to Locally Served DNS Zones Registry
> Date:     2025-12-02
> Group:    Individual Submission
> Pages:    4
> URL:      https://www.ietf.org/archive/id/draft-dnsop-rfc6303-bis-00.txt
> Status:   https://datatracker.ietf.org/doc/draft-dnsop-rfc6303-bis/
> HTML:     https://www.ietf.org/archive/id/draft-dnsop-rfc6303-bis-00.html
> HTMLized: https://datatracker.ietf.org/doc/html/draft-dnsop-rfc6303-bis
> 
> 
> Abstract:
> 
>    RFC 6063, "Locally Served DNS Zones", defines two IANA registries
>    called "IPv4 Locally-Served DNS Zone Registry" and "IPv6 Locally-
>    Served DNS Zone Registry".  This document changes the registration
>    procedure for that registry from "IETF Review" to "Expert Review".
>    This document updates RFC 6063.
> ____________________________________________________________________________________________________________
> Ce message et ses pieces jointes peuvent contenir des informations confidentielles ou privilegiees et ne doivent donc
> pas etre diffuses, exploites ou copies sans autorisation. Si vous avez recu ce message par erreur, veuillez le signaler
> a l'expediteur et le detruire ainsi que les pieces jointes. Les messages electroniques etant susceptibles d'alteration,
> Orange decline toute responsabilite si ce message a ete altere, deforme ou falsifie. Merci.
>  
> This message and its attachments may contain confidential or privileged information that may be protected by law;
> they should not be distributed, used or copied without authorisation.
> If you have received this email in error, please notify the sender and delete this message and its attachments.
> As emails may be altered, Orange is not liable for messages that have been modified, changed or falsified.
> Thank you.
> ____________________________________________________________________________________________________________
> Ce message et ses pieces jointes peuvent contenir des informations confidentielles ou privilegiees et ne doivent donc
> pas etre diffuses, exploites ou copies sans autorisation. Si vous avez recu ce message par erreur, veuillez le signaler
> a l'expediteur et le detruire ainsi que les pieces jointes. Les messages electroniques etant susceptibles d'alteration,
> Orange decline toute responsabilite si ce message a ete altere, deforme ou falsifie. Merci.
> 
> This message and its attachments may contain confidential or privileged information that may be protected by law;
> they should not be distributed, used or copied without authorisation.
> If you have received this email in error, please notify the sender and delete this message and its attachments.
> As emails may be altered, Orange is not liable for messages that have been modified, changed or falsified.
> Thank you.
> _______________________________________________
> DNSOP mailing list -- dnsop@ietf.org
> To unsubscribe send an email to dnsop-leave@ietf.org

-- 
Mark Andrews, ISC
1 Seymour St., Dundas Valley, NSW 2117, Australia
PHONE: +61 2 9871 4742              INTERNET: marka@isc.org