Re: [DNSOP] [Ext] Re: draft-ietf-dnsop-extended-error and combinations of EDEs and RCODEs

Wes Hardaker <> Fri, 27 September 2019 23:43 UTC

Return-Path: <>
Received: from localhost (localhost []) by (Postfix) with ESMTP id 70CFC120072 for <>; Fri, 27 Sep 2019 16:43:32 -0700 (PDT)
X-Virus-Scanned: amavisd-new at
X-Spam-Flag: NO
X-Spam-Score: -1.899
X-Spam-Status: No, score=-1.899 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Received: from ([]) by localhost ( []) (amavisd-new, port 10024) with ESMTP id sYu7P1GaD2si for <>; Fri, 27 Sep 2019 16:43:31 -0700 (PDT)
Received: from ( []) (using TLSv1.2 with cipher ADH-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by (Postfix) with ESMTPS id 30DFB120026 for <>; Fri, 27 Sep 2019 16:43:31 -0700 (PDT)
Received: from localhost (unknown []) by (Postfix) with ESMTPA id 8C3942DD7C; Fri, 27 Sep 2019 16:43:22 -0700 (PDT)
From: Wes Hardaker <>
To: Tony Finch <>
References: <> <> <> <> <> <> <> <> <> <> <> <> <> <> <> <>
Date: Fri, 27 Sep 2019 16:43:21 -0700
In-Reply-To: <> (Tony Finch's message of "Fri, 13 Sep 2019 21:01:33 +0100")
Message-ID: <>
User-Agent: Gnus/5.13 (Gnus v5.13) Emacs/26.1 (gnu/linux)
MIME-Version: 1.0
Content-Type: text/plain
Archived-At: <>
Subject: Re: [DNSOP] [Ext] Re: draft-ietf-dnsop-extended-error and combinations of EDEs and RCODEs
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: IETF DNSOP WG mailing list <>
List-Unsubscribe: <>, <>
List-Archive: <>
List-Post: <>
List-Help: <>
List-Subscribe: <>, <>
X-List-Received-Date: Fri, 27 Sep 2019 23:43:33 -0000

Tony Finch <> writes:

> Some questions about the intended meanings...

Thanks Tony,

Thanks for the comments.  Responses are inline below in my tracking
notes below.

14.9 DONE Tony Finch in a sub thread to Paul

  Some questions about the intended meanings...

14.9.1 DONE 3.6.  Extended DNS Error Code 5 - DNSSEC Indeterminate

  If I remember correctly, there isn't a consistent definition of what
  "indeterminate" means. Perhaps it's worth adding a reference to the
  intended definition.

  [ actually maybe all the codes could have citations to where the error
  cases are mentioned in existing specifications, perhaps with a comment
  that the citations are not intended to be exhausive ]

  + Response: good point.  I'll use a reference to 4035.  We'll have to
    collect references for the rest...  That's a good (and painful)

14.9.2 DONE 3.5.  Extended DNS Error Code 4 - Forged Answer

  3.16.  Extended DNS Error Code 15 - Blocked 3.17.  Extended DNS Error
  Code 16 - Censored 3.19.  Extended DNS Error Code 18 - Filtered

  I don't understand the shades of meaning that these are supposed to

  wrt "filtered", the description implies vaguely RPZ flavoured
  filtering, but it mentions a REFUSED RCODE which isn't what a sensible
  implementation would use for that purpose, so I am more confused.

  3.18.  Extended DNS Error Code 17 - Prohibited

  If I understand correctly, the four above are about the qname whereas
  this is about the client? The ordering is a bit confusing.

  + Response: Those three codes were supplied in a previous comment
    round and they are supposed to indicate policies being applied from
    different sources.  Can you check the new text of them to see if
    they are more understandable now?

14.9.3 DONE 3.21.  Extended DNS Error Code 20 - Lame

  This needs to be split into two: server doesn't know about the zone
  queried for (typically RCODE=REFUSED), and server knows about the zone
  but it has expired (typically RCODE=SERVFAIL).

  Resolvers handling RD=0 queries typically answer from cache or would
  answer REFUSED/Prohibited, I would have thought.

  + Response: I created an "Invalid Data" error code to handle this.
    Does this work for you?

Wes Hardaker