Re: [DNSOP] Call for Adoption: draft-andrews-dnsop-glue-is-not-optional

Paul Vixie <> Fri, 22 May 2020 01:36 UTC

Return-Path: <>
Received: from localhost (localhost []) by (Postfix) with ESMTP id 2D1F83A0D68 for <>; Thu, 21 May 2020 18:36:07 -0700 (PDT)
X-Virus-Scanned: amavisd-new at
X-Spam-Flag: NO
X-Spam-Score: -1.9
X-Spam-Status: No, score=-1.9 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from ([]) by localhost ( []) (amavisd-new, port 10024) with ESMTP id pave2OlESzxx for <>; Thu, 21 May 2020 18:36:03 -0700 (PDT)
Received: from ( [IPv6:2001:559:8000:cd::5]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by (Postfix) with ESMTPS id E27553A0C3D for <>; Thu, 21 May 2020 18:36:02 -0700 (PDT)
Received: from linux-9daj.localnet ( []) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client did not present a certificate) by (Postfix) with ESMTPSA id 4737CB074A; Fri, 22 May 2020 01:35:59 +0000 (UTC)
From: Paul Vixie <>
Date: Fri, 22 May 2020 01:35:58 +0000
Message-ID: <2579854.HOIbhPnuQa@linux-9daj>
Organization: none
In-Reply-To: <>
References: <> <>
MIME-Version: 1.0
Content-Transfer-Encoding: 7Bit
Content-Type: text/plain; charset="us-ascii"
Archived-At: <>
Subject: Re: [DNSOP] Call for Adoption: draft-andrews-dnsop-glue-is-not-optional
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: IETF DNSOP WG mailing list <>
List-Unsubscribe: <>, <>
List-Archive: <>
List-Post: <>
List-Help: <>
List-Subscribe: <>, <>
X-List-Received-Date: Fri, 22 May 2020 01:36:07 -0000

On Friday, 22 May 2020 00:31:34 UTC Masataka Ohta wrote:
> ...
> While I'm not against the clarification, the draft should mention
> that rfc1034 already states:
>     To fix this problem, a zone contains "glue" RRs which are not
>     part of the authoritative data, and are address RRs for the servers.
>     These RRs are only necessary if the name server's name is "below" the
>     ^^^^^^^^^^^^^^^^^^^^^^^^^^^^
>     cut, and are only used as part of a referral response.
>                  ^^^^^^^^^
> which means the glue RRs are necessary for a referral response.
> Though not very obvious, it logically means that they MUST be
> included as part of a referral response, because it is the only
> reason to make them necessary.

i agree. this is why later versions of BIND would return referrals rather than 
answers when queried for these names, which were in-bailiwick but below-zone. 
by implication, they can only be retrieved from the delegating server as part 
of a referral, and they will be in the additional section not the answer 
section even though they do match the qname. this distinction is also 
necessary in the assignment of credibility levels in the downstream cache.