Re: [DNSOP] Fw: New Version Notification for draft-arnt-yao-dnsop-root-data-caching-00.txt

Bob Harold <rharolde@umich.edu> Thu, 14 February 2019 21:42 UTC

Return-Path: <rharolde@umich.edu>
X-Original-To: dnsop@ietfa.amsl.com
Delivered-To: dnsop@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 06D3B1311E6 for <dnsop@ietfa.amsl.com>; Thu, 14 Feb 2019 13:42:13 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.999
X-Spam-Level:
X-Spam-Status: No, score=-1.999 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=umich.edu
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 8VRz_RKCuY6G for <dnsop@ietfa.amsl.com>; Thu, 14 Feb 2019 13:42:09 -0800 (PST)
Received: from mail-lj1-x230.google.com (mail-lj1-x230.google.com [IPv6:2a00:1450:4864:20::230]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id A43E11311E3 for <dnsop@ietf.org>; Thu, 14 Feb 2019 13:42:09 -0800 (PST)
Received: by mail-lj1-x230.google.com with SMTP id g11-v6so6597698ljk.3 for <dnsop@ietf.org>; Thu, 14 Feb 2019 13:42:09 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=umich.edu; s=google-2016-06-03; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=IyidUsbUx9//LZ96ln8BCOx1degSzzxKsbbUVUAy3Y0=; b=hk6LnfQiM0fs20RWAwecSl3UkwzK+mTZ8s5Aj5hESdxlJ/nBWE7DtxXRNW8E+TqD7E piWGKefY+5K07JgbSiE/XhV/gA/dlyEIDFZJcAA+MQQJ2A3XvFVLSyhWttNgU2dmhUvD IIpgDFlkknjgJeB3yifOTKDfaiZVA0RpR+Y+RWFwLSr6Vov/3Q/do/8cbXdUKQM+dMJQ Nd0ZNccpHnvSskusuj+YnkO/cyeMSPQuFmUUwMVFaeIXBpFq68PbwrGc/GLOdNF2QC/x w0k1m7j0Qke+lKTopyX2nQzkylNCpxvyideDPOoGB1cAYzBfvtV+rBquFUUNSj0YDX/d gAMg==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=IyidUsbUx9//LZ96ln8BCOx1degSzzxKsbbUVUAy3Y0=; b=Dl+q+Kl0+XIH9tPhODSoU6QsljYmLh8Wadm11bGbhm04naGtRBNCF1dpUMpBXrMEy0 L94yEzrn/PmF+MLR8eV/2WaTkp3vQOj9DCpMYhvCFVilLsuwjqSLfDHH2LFi3VJOQ+oO Kg8hWysCM2g+peX1GzzG4sm6CGwuz5vSOrCTBhXZjaCXnWcM7F5ceCYedKWv7Jh8z4b/ rj77KlBs0A4IO0MuEwfQIncP1o2yIbl1zIIWFQMwrTOYiX7e0231DggrCrsEuRefISzW FfmBjhAQjTv2oXw+OIgvg6r8nBRaWOpd+We1Mr8JBCJCjSuwRjn4JjWlstmYSZAGGwof tIaQ==
X-Gm-Message-State: AHQUAua0wYlYM+FtEYDQxSkCOOM0a+C3GlasbP0rHhFLePHAOSQxafOm aFWxhbNMR+bqv4qxa/3QypgmglpBw6wNZChcMQ4wAA==
X-Google-Smtp-Source: AHgI3IbS7InUMbnYsG635C1n/oVXE1/mhRK+59XImwyAZvPkraXNMZPG0b5NhuaPwiUfD+rK5GIJYGA3lZ5BpMAblLM=
X-Received: by 2002:a2e:84ca:: with SMTP id q10-v6mr3659618ljh.65.1550180527545; Thu, 14 Feb 2019 13:42:07 -0800 (PST)
MIME-Version: 1.0
References: <4d51e683.32d.168ea651be8.Coremail.yaojk@cnnic.cn> <alpine.DEB.2.20.1902141349060.18720@grey.csi.cam.ac.uk> <587d85ee-73bc-40f4-aae8-550d877ca6d1@gulbrandsen.priv.no>
In-Reply-To: <587d85ee-73bc-40f4-aae8-550d877ca6d1@gulbrandsen.priv.no>
From: Bob Harold <rharolde@umich.edu>
Date: Thu, 14 Feb 2019 16:41:56 -0500
Message-ID: <CA+nkc8Bkpr7PDSyWjGQftaODj7pffmzWJUeYghGScFLi0CyHpw@mail.gmail.com>
To: Arnt Gulbrandsen <arnt@gulbrandsen.priv.no>
Cc: Tony Finch <dot@dotat.at>, Jiankang Yao <yaojk@cnnic.cn>, IETF DNSOP WG <dnsop@ietf.org>
Content-Type: multipart/alternative; boundary="000000000000aeafeb0581e1871a"
Archived-At: <https://mailarchive.ietf.org/arch/msg/dnsop/HfOrqj3JpFklJ8dnWUWWekUq_zU>
Subject: Re: [DNSOP] Fw: New Version Notification for draft-arnt-yao-dnsop-root-data-caching-00.txt
X-BeenThere: dnsop@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dnsop>, <mailto:dnsop-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dnsop/>
List-Post: <mailto:dnsop@ietf.org>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dnsop>, <mailto:dnsop-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 14 Feb 2019 21:42:13 -0000

On Thu, Feb 14, 2019 at 12:29 PM Arnt Gulbrandsen <arnt@gulbrandsen.priv.no>
wrote:

> On Thursday 14 February 2019 14:58:58 CET, Tony Finch wrote:
> > How does this relate to:
> >
> > https://tools.ietf.org/html/draft-wkumari-dnsop-hammer
> > https://tools.ietf.org/html/draft-ietf-dnsop-7706bis
>
> It originates in various ideas Jiankang and I have chatted about.
>
> I didn't like 7706, because I feel that the servers that have long ping
> times to the nearest root are more likely to have admins who make
> mistakes.
> Jiankang and I discussed alternatives when we met a while ago, and a few
> times since. Once we hit upon this possibility, we didn't discuss
> draft-wkumari-dnsop-hammer, perhaps because it's expired and we'd
> forgotten. Mental entropy.
>
> Compared to the hammer draft, I should say that this is dead simple, has
> one fewer acronyms, and that both of those are intentional features.
>
> I see your name is in the text. Why did you let it expire?
>
> > It looks like this new draft is actually a revision of:
> >
> > https://tools.ietf.org/html/draft-yao-dnsop-root-cache
>
> Probably correct. IIt was I who did the typing, and I prefer to start by
> editing something that already has the right XML stuff and at least some
> references etc.
>
> Arnt
>

The draft assumes typical TTL is a week, but what I see in the root zone is:
 the records for X.root-servers.net are 6 days (518400),
DS, NSEC, RRSIG, and SOA are 1 day (86400), and
 A, AAAA, DNSKEY, and NS are all 2 days (172800).
I assume the NS records are the most often used?

So I think the draft needs to recalculate the numbers with 2 days as the
typical ttl.

awk '{print $2,$4}' root.zone | sort | uniq -c
      2
   4159 172800 A
   3648 172800 AAAA
      3 172800 DNSKEY
   7269 172800 NS
      2 172800 RRSIG
     13 518400 A
     13 518400 AAAA
     13 518400 NS
      1 518400 RRSIG
   2903 86400 DS
   1536 86400 NSEC
   2926 86400 RRSIG
      2 86400 SOA
      1 <<>> 9.11.3-1ubuntu1.3-Ubuntu
      1 global +cmd
      1 Query 8197
      1 SERVER:
      1 WHEN: Feb
      1 XFR 22488

-- 
Bob Harold