[DNSOP] Re: [v6ops] Re: Re: Moving DNS64 (RFC6147) to Internet Standard
"jordi.palet@consulintel.es" <jordi.palet@consulintel.es> Sat, 11 April 2026 08:13 UTC
Return-Path: <prvs=1561945371=jordi.palet@consulintel.es>
X-Original-To: dnsop@mail2.ietf.org
Delivered-To: dnsop@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 9FD72DA45E0E; Sat, 11 Apr 2026 01:13:03 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1775895183; bh=ce1N0+r6VEMOo0WMTq5evDacXqAJKjQgLjtMLVOkPfw=; h=Subject:From:In-Reply-To:Date:Cc:References:To; b=T+Xq6FeYZG4/n03EzMMvm2wsaXNckE/cYKS9BIK+jw4NIq9WWCkPFkRJHw4L/4nON OSU9fKAB5t8X15iAYzGLJJMXwcPXblTbICxENR+jpxBTJeHrlIk1Z27UfynV4xVWiM Ih2pejIh4B2Nf9YX8bUzL2dC5pupfzadEGYffdD4=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -1.999
X-Spam-Level:
X-Spam-Status: No, score=-1.999 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=consulintel.es
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id WFBrae2ha8Q1; Sat, 11 Apr 2026 01:13:03 -0700 (PDT)
Received: from mail.consulintel.es (mail.consulintel.es [IPv6:2001:470:1f09:495::5]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 0452EDA45E08; Sat, 11 Apr 2026 01:13:02 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=consulintel.es; s=mailer; t=1775895182; x=1776499982; i=jordi.palet@consulintel.es; q=dns/txt; h=Content-Type: Mime-Version:Subject:From:In-Reply-To:Date:Cc: Content-Transfer-Encoding:Message-Id:References:To; bh=ce1N0+r6V EMOo0WMTq5evDacXqAJKjQgLjtMLVOkPfw=; b=dYi7pagFfxcwVFbqkrmMft1fp 4CJApBUCNOaZlV2l9xm9ky4n56bNQCKaUtLUQ2ZlGyB9fKw/eiRBHch0MvONs9pa bas3DvJr1SgVVfSTkm3oMDU0jsKZtCAZn/jX1WufRzI2ZjCCZk/J1dq1s//xVVmm BiiU5dm2EMWFu4ChUHv45cpgZ5cmfKhtcsQs51DD30hSFk2u//XKq0oO7cMRH8P3 H3GbjoScCs7nugZiEgSOjT4qbF7Tz8g7eo8iLzWbYpbJpiAEsNqLo6MrUVokX4cY JkWfZYIFukuIgP//QjgY4Ws6rqDKdFJtWqEXaNngr8P9C+LyvHtowhz0GUu3Q==
X-MDAV-Processed: mail.consulintel.es, Sat, 11 Apr 2026 10:13:02 +0200 (not processed: message from trusted source)
X-Spam-Processed: mail.consulintel.es, Sat, 11 Apr 2026 10:13:01 +0200
Received: from smtpclient.apple by mail.consulintel.es (10.10.10.5) (MDaemon PRO v25.5.0) with ESMTPSA id md5001002618767.msg; Sat, 11 Apr 2026 10:13:01 +0200
X-MDRemoteIP: 2001:470:1f09:495:c5db:75f:ddd9:542e
X-MDArrival-Date: Sat, 11 Apr 2026 10:13:01 +0200
X-Authenticated-Sender: jordi.palet@consulintel.es
X-Return-Path: prvs=1561945371=jordi.palet@consulintel.es
X-Envelope-From: jordi.palet@consulintel.es
Content-Type: text/plain; charset="utf-8"
Mime-Version: 1.0 (Mac OS X Mail 16.0 \(3864.500.181\))
From: "jordi.palet@consulintel.es" <jordi.palet@consulintel.es>
In-Reply-To: <m1wB6jW-0000VYC@stereo.hq.phicoh.net>
Date: Sat, 11 Apr 2026 10:12:48 +0200
Content-Transfer-Encoding: quoted-printable
Message-Id: <9A70D5B5-F58A-471E-9CC6-7A0874B53B80@consulintel.es>
References: <m1wAunU-0000NEC@stereo.hq.phicoh.net> <2338256.t9SDvczpPo@localhost> <038ae9d1-34fc-4085-aa6d-76ef79287857@gmail.com> <PARP264MB6760A67BB8F2060962E8A64088592@PARP264MB6760.FRAP264.PROD.OUTLOOK.COM> <B93DB6C8-2974-4915-93DE-DFCB6B858AFA@consulintel.es> <m1wB6jW-0000VYC@stereo.hq.phicoh.net>
To: dnsop@ietf.org
X-Mailer: Apple Mail (2.3864.500.181)
X-MDCFSigsAdded: consulintel.es
Message-ID-Hash: I4GA5URN35T42TZUUKTFQO5A45KK7VIR
X-Message-ID-Hash: I4GA5URN35T42TZUUKTFQO5A45KK7VIR
X-MailFrom: prvs=1561945371=jordi.palet@consulintel.es
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-dnsop.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: IPv6 Operations <v6ops@ietf.org>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [DNSOP] Re: [v6ops] Re: Re: Moving DNS64 (RFC6147) to Internet Standard
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/dnsop/DBpwqvU245GLwVmaWsrvU82eJxI>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dnsop>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Owner: <mailto:dnsop-owner@ietf.org>
List-Post: <mailto:dnsop@ietf.org>
List-Subscribe: <mailto:dnsop-join@ietf.org>
List-Unsubscribe: <mailto:dnsop-leave@ietf.org>
Hi Philip, In-line below. Regards, Jordi @jordipalet > El 10 abr 2026, a las 9:56, Philip Homburg <pch-dnsop-7@u-1.phicoh.com> escribió: > >> 3) If the people deploys DNSSEC together with IPv6, >> DNS64 is not creating any trouble. It doesnt make sense to me that >> DNSSEC is deployed without IPv6, right? > > Let me give you random popular site: slack.com. > > It does have DNSSEC, it doesn't have IPv6. Can we live if the real > world please? > > IPv6 and DNSSEC are independent technologies. We cannot assume that one > implies the other. And do you have real experience of deployments breaking it? I will love to see those cases. I just tested in a couple of deployments that I’ve access to. It worked. I think the point is to understand that DNSSEC with DNS64 is broken only in a very very very small % of situation, which can also be resolved. > > 4) When DNSSEC is deployed >> without IPv6, in most of the cases no problems is created and what >> we probably want to encourage is to do DNS64 self-synthesis in the >> hosts if they are checking DNSSEC. See section 4.1 of RFC8683. > > This is a very roundabout way of saying the DNS64 just doesn't work for > hosts that do local DNSSEC validation. > > It limitations like this (and the lack of support for IPv4 literals, > issues with applications using public DNS resolvers (with or with out > DoT or DoH) that mean that DNS64 should have a very reduced scope. > No, is not the case. You just need to make sure how you do a correct deployment of the DNS64 servers. Any protocol may fail if incorrectly deployed. The failure rate is different from protocol to protocol when wrongly deployed. > One thing that I don't understand, is how (in the context of DNS64) > applications handle NAT traversal. > > As far as I know, for NAT traversal you have to know if an address is IPv4 > or IPv6. But DNS64 hides that difference. Is there an RFC where this is > spelled out? > I see Michael already provided a good response to this point. Basically this is NAT64 issue, and once more, in real deployments I’ve not seen this being a problem. Happy to hear otherwise. ********************************************** IPv4 is over Are you ready for the new Internet ? http://www.theipv6company.com The IPv6 Company This electronic message contains information which may be privileged or confidential. The information is intended to be for the exclusive use of the individual(s) named above and further non-explicilty authorized disclosure, copying, distribution or use of the contents of this information, even if partially, including attached files, is strictly prohibited and will be considered a criminal offense. If you are not the intended recipient be aware that any disclosure, copying, distribution or use of the contents of this information, even if partially, including attached files, is strictly prohibited, will be considered a criminal offense, so you must reply to the original sender to inform about this communication and delete it.
- [DNSOP] Moving DNS64 (RFC6147) to Internet Standa… mohamed.boucadair
- [DNSOP] Re: [v6ops] Moving DNS64 (RFC6147) to Int… Scott Morizot
- [DNSOP] Re: Moving DNS64 (RFC6147) to Internet St… Philip Homburg
- [DNSOP] Re: Moving DNS64 (RFC6147) to Internet St… Paul Vixie
- [DNSOP] Re: [v6ops] Re: Re: Moving DNS64 (RFC6147… Brian E Carpenter
- [DNSOP] Re: [v6ops] Re: Re: Moving DNS64 (RFC6147… mohamed.boucadair
- [DNSOP] Re: [v6ops] Moving DNS64 (RFC6147) to Int… Chenhao Ma
- [DNSOP] Re: [v6ops] Re: Re: Moving DNS64 (RFC6147… Ole Trøan
- [DNSOP] Re: [v6ops] Re: Re: Moving DNS64 (RFC6147… Philip Homburg
- [DNSOP] Re: [v6ops] Re: Re: Re: Moving DNS64 (RFC… Michael Richardson
- [DNSOP] Re: [v6ops] Re: Re: Moving DNS64 (RFC6147… Michael Richardson
- [DNSOP] Re: [Ext] Re: [v6ops] Re: Re: Re: Moving … Paul Hoffman
- [DNSOP] Re: [v6ops] Re: Re: Moving DNS64 (RFC6147… Philip Homburg
- [DNSOP] Re: [v6ops] Re: Re: Re: Re: Moving DNS64 … Nick Buraglio
- [DNSOP] Re: [v6ops] Moving DNS64 (RFC6147) to Int… Dan Wing
- [DNSOP] Re: [v6ops] Moving DNS64 (RFC6147) to Int… Philip Homburg
- [DNSOP] Re: [v6ops] Moving DNS64 (RFC6147) to Int… Ole Trøan
- [DNSOP] Re: [Ext] Re: [v6ops] Re: Re: Re: Moving … Michael Richardson
- [DNSOP] Re: [v6ops] Re: Re: Moving DNS64 (RFC6147… jordi.palet@consulintel.es
- [DNSOP] Re: [v6ops] Re: Re: Moving DNS64 (RFC6147… jordi.palet@consulintel.es
- [DNSOP] Re: [v6ops] Re: Re: Moving DNS64 (RFC6147… Philip Homburg
- [DNSOP] Re: [v6ops] Re: Re: Moving DNS64 (RFC6147… Michael Richardson
- [DNSOP] Re: [v6ops] Re: Re: Moving DNS64 (RFC6147… jordi.palet@consulintel.es
- [DNSOP] Re: [v6ops] [Ext] Re: Re: Re: Re: Moving … jordi.palet@consulintel.es
- [DNSOP] Re: [v6ops] Re: Re: Moving DNS64 (RFC6147… jordi.palet@consulintel.es
- [DNSOP] Re: [v6ops] Moving DNS64 (RFC6147) to Int… mohamed.boucadair
- [DNSOP] Re: [v6ops] Re: Re: Re: Moving DNS64 (RFC… jordi.palet@consulintel.es
- [DNSOP] Re: [v6ops] Re: Re: Re: Moving DNS64 (RFC… Gert Doering
- [DNSOP] Re: [v6ops] Re: Re: Moving DNS64 (RFC6147… jordi.palet@consulintel.es
- [DNSOP] Re: [v6ops] Re: Re: Moving DNS64 (RFC6147… Philip Homburg
- [DNSOP] Re: [v6ops] Re: Re: Re: Moving DNS64 (RFC… Tim Chown
- [DNSOP] Re: [v6ops] Re: Re: Re: Moving DNS64 (RFC… jordi.palet@consulintel.es
- [DNSOP] Re: [v6ops] Re: Re: Re: Moving DNS64 (RFC… Philip Homburg
- [DNSOP] Re: [v6ops] Re: Re: Moving DNS64 (RFC6147… jordi.palet@consulintel.es
- [DNSOP] Re: [v6ops] Re: Re: Re: Moving DNS64 (RFC… Michael Richardson
- [DNSOP] Re: [v6ops] Re: Re: Moving DNS64 (RFC6147… jordi.palet@consulintel.es
- [DNSOP] Re: [v6ops] Re: Re: Re: Re: Moving DNS64 … Brian E Carpenter
- [DNSOP] Re: [Ext] Re: [v6ops] Re: Re: Re: Moving … Warren Kumari
- [DNSOP] Re: [Ext] Re: [v6ops] Re: Re: Re: Moving … jordi.palet@consulintel.es
- [DNSOP] Re: [v6ops] Re: Re: Moving DNS64 (RFC6147… jordi.palet@consulintel.es
- [DNSOP] Re: [v6ops] Re: Re: Re: Moving DNS64 (RFC… Philip Homburg
- [DNSOP] Re: [v6ops] Re: Re: Re: Re: Moving DNS64 … Ted Lemon
- [DNSOP] Re: [v6ops] Re: Re: Re: Re: Re: Moving DN… Mark Andrews
- [DNSOP] Re: [v6ops] Re: Re: Re: Re: Re: Moving DN… Mark Andrews
- [DNSOP] Re: [v6ops] Re: [Ext] Re: Re: Re: Re: Mov… Michael Richardson
- [DNSOP] Re: [v6ops] Re: Re: Re: Re: Re: Moving DN… Brian E Carpenter
- [DNSOP] Re: [v6ops] Re: Re: Re: Moving DNS64 (RFC… Michael Richardson
- [DNSOP] Re: [v6ops] Re: Re: Moving DNS64 (RFC6147… Michael Richardson
- [DNSOP] Re: [v6ops] Re: [Ext] Re: Re: Re: Re: Mov… Brian E Carpenter
- [DNSOP] Re: [v6ops] Re: Re: Re: Re: Moving DNS64 … jordi.palet@consulintel.es
- [DNSOP] Re: [v6ops] Re: Re: Re: Re: Moving DNS64 … jordi.palet@consulintel.es
- [DNSOP] Re: [v6ops] Re: Re: Re: Re: Moving DNS64 … jordi.palet@consulintel.es
- [DNSOP] Re: [v6ops] Re: Re: Re: Re: Moving DNS64 … Philip Homburg
- [DNSOP] Re: [v6ops] Re: Re: Re: Re: Moving DNS64 … jordi.palet@consulintel.es
- [DNSOP] Re: [v6ops] Re: Re: Re: Moving DNS64 (RFC… Philip Homburg
- [DNSOP] Re: [v6ops] Re: Re: Re: Re: Moving DNS64 … marka
- [DNSOP] (Concluded) RE: Moving DNS64 (RFC6147) to… mohamed.boucadair
- [DNSOP] Re: (Concluded) RE: Moving DNS64 (RFC6147… jordi.palet@consulintel.es
- [DNSOP] Re: [v6ops] Re: Re: Re: Re: Moving DNS64 … jordi.palet@consulintel.es
- [DNSOP] Re: [v6ops] Re: Re: Re: Re: Moving DNS64 … jordi.palet@consulintel.es
- [DNSOP] Re: [v6ops] Re: Re: Re: Re: Re: Moving DN… Philip Homburg
- [DNSOP] Re: (Concluded) RE: Moving DNS64 (RFC6147… Philipp Tiesel
- [DNSOP] Re: (Concluded) RE: Moving DNS64 (RFC6147… jordi.palet@consulintel.es