Re: [DNSOP] Minimum viable ANAME

Olli Vanhoja <> Tue, 26 March 2019 19:31 UTC

Return-Path: <>
Received: from localhost (localhost []) by (Postfix) with ESMTP id D30501209A4 for <>; Tue, 26 Mar 2019 12:31:49 -0700 (PDT)
X-Virus-Scanned: amavisd-new at
X-Spam-Flag: NO
X-Spam-Score: -1.236
X-Spam-Status: No, score=-1.236 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_MED=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_SOFTFAIL=0.665] autolearn=no autolearn_force=no
Authentication-Results: (amavisd-new); dkim=pass (2048-bit key)
Received: from ([]) by localhost ( []) (amavisd-new, port 10024) with ESMTP id MPaY4bDfooT2 for <>; Tue, 26 Mar 2019 12:31:48 -0700 (PDT)
Received: from ( [IPv6:2a00:1450:4864:20::233]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by (Postfix) with ESMTPS id B88A21208BE for <>; Tue, 26 Mar 2019 12:31:46 -0700 (PDT)
Received: by with SMTP id r24so11154150ljg.3 for <>; Tue, 26 Mar 2019 12:31:46 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;; s=20150623; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=9XN9r7u2nd9HNiQ+L+Z2Niqx4L3UrcyVhBRxEhUAXWs=; b=z5Zmcet3oINYSdl7SKmaS+XgG4FaHgbmu9xa16qEZ7x6QDcJeTBY3DNVWXH0x3AhxM SqG6PoNsJukPQ4Gd5AzBuYBho6gVCQybgM16tzzDqaAdNmJhnre9ukZeCocEfBLUzVfZ yQETK/lzrKcw2RU+1NC+xKBgjPb2kk0onBLlqER2dj5g9vZ+I8XRcrTwrQWdXoidcp/p 6DJnjbVjWEbQxupJIdwL1VgZq2Z++TH1GsgGSvE4U4czkF5Owzj6GYrguaYjiu3R32i/ EoMcvIo2sgkTT+jf4KmwzY9q1YP4WbU3nMktMtBuT5i6CdIBghAcgxZ80KhVaVoTt6gF uk/w==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=9XN9r7u2nd9HNiQ+L+Z2Niqx4L3UrcyVhBRxEhUAXWs=; b=VpWD5wQyHsJ+KiQuNFoxGzzHLXAuWYA0NaMvVQgRcJIcAEitYS1e8PNAIYiwc3XeI7 JeURq3/R1qqp9z09SqGZiIqor91b+uklj/+QX8oGdqCq9ObFVvvl1FReOJjwj2ZGDKbS 0qDlGLrKGHjSJ6r8RBZwtD6hz2ve2IPEKQX8mzWp4zQs8yF4sytgfTZMlh1sSD6o88rK MgSV83nWpDxd4jJvcg0hbC2dngtBOD3jKHWhpnYmSCERFrgwvYxyHfOyu8hTPQS2/mjJ mMPTq4NoAqxfuYHAooT47ClhkRodRvavjcLAtQvC26IXocyYEf7gfPYo7SmFlEo9vz20 UJ4g==
X-Gm-Message-State: APjAAAXDhN3Rm6sXs+e3DXLcKuNB3cSu87BA7I5fKaiEQ8Nps6QtVytE 8a3MHLmQbcE73VOhG4bRnKMapq79FxA4qXM75SNk1A==
X-Google-Smtp-Source: APXvYqx55n2YYCDoMLjjDEua8YmCc8mv1jMiR1Bjch7c+AVQ+pykeBBiCIgGXVwoTn7kvY61K4mVdJ8hQMbpCwoqgrY=
X-Received: by 2002:a2e:5d94:: with SMTP id v20mr15996096lje.138.1553628704945; Tue, 26 Mar 2019 12:31:44 -0700 (PDT)
MIME-Version: 1.0
References: <20180919201401.8E0C220051382A@ary.qy> <> <20180920061343.GA754@jurassic> <> <> <> <> <> <> <> <> <>
In-Reply-To: <>
From: Olli Vanhoja <>
Date: Tue, 26 Mar 2019 20:31:33 +0100
Message-ID: <>
To: Brian Dickson <>
Cc: =?UTF-8?B?VmxhZGltw61yIMSMdW7DoXQ=?= <>, Tony Finch <>, dnsop <>
Content-Type: text/plain; charset="UTF-8"
Archived-At: <>
Subject: Re: [DNSOP] Minimum viable ANAME
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: IETF DNSOP WG mailing list <>
List-Unsubscribe: <>, <>
List-Archive: <>
List-Post: <>
List-Help: <>
List-Subscribe: <>, <>
X-List-Received-Date: Tue, 26 Mar 2019 19:31:50 -0000

On Tue, Mar 26, 2019 at 7:23 PM Brian Dickson
> We need to start with the base requirements, which is, "I want an apex RR that allows HTTP browser indirection just as if there was a CNAME there".
> Sibling records do not behave like CNAMEs, no matter what extra hacks get applied; CNAME processing is done by the resolver.
> The options are, new RRtypes that require resolver upgrades, or RRtypes that are handled by the client application (browser), which benefit from (but do not require) resolver upgrades.

I see a huge problem there, let's call it IPv6 problem. During the
transition phase to this new RR we need to have a fallback, right? How
long do we need to have that fallback for old resolvers and browsers?
I'd say approximately until DNS has been replaced by some other tech.
If we are lucky DoH would solve it by doing what those previously
mentioned companies are doing now on their servers, but then we would
cry again that it's the wrong solution.