Re: [DNSOP] Clarifying referrals (#35)

Tony Finch <dot@dotat.at> Wed, 15 November 2017 12:18 UTC

Return-Path: <dot@dotat.at>
X-Original-To: dnsop@ietfa.amsl.com
Delivered-To: dnsop@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 31BD3129409 for <dnsop@ietfa.amsl.com>; Wed, 15 Nov 2017 04:18:31 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.199
X-Spam-Level:
X-Spam-Status: No, score=-4.199 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 4GbYhjNQLcLq for <dnsop@ietfa.amsl.com>; Wed, 15 Nov 2017 04:18:29 -0800 (PST)
Received: from ppsw-32.csi.cam.ac.uk (ppsw-32.csi.cam.ac.uk [131.111.8.132]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id A0495129401 for <dnsop@ietf.org>; Wed, 15 Nov 2017 04:18:29 -0800 (PST)
X-Cam-AntiVirus: no malware found
X-Cam-ScannerInfo: http://help.uis.cam.ac.uk/email-scanner-virus
Received: from grey.csi.cam.ac.uk ([131.111.57.57]:42131) by ppsw-32.csi.cam.ac.uk (ppsw.cam.ac.uk [131.111.8.136]:25) with esmtps (TLSv1:ECDHE-RSA-AES256-SHA:256) id 1eEweA-000gQr-0w (Exim 4.89) (return-path <dot@dotat.at>); Wed, 15 Nov 2017 12:18:26 +0000
Date: Wed, 15 Nov 2017 12:18:25 +0000
From: Tony Finch <dot@dotat.at>
To: Paul Vixie <paul@redbarn.org>
cc: Dave Lawrence <tale@dd.org>, dnsop@ietf.org
In-Reply-To: <5A0BB7B5.8050804@redbarn.org>
Message-ID: <alpine.DEB.2.11.1711151137290.32058@grey.csi.cam.ac.uk>
References: <20171113014445.ncldrwnuuvluecx7@mx4.yitter.info> <5A08FD96.8030907@redbarn.org> <20171113020736.ga7rzgst2hurb56h@mx4.yitter.info> <5A09068A.3030206@redbarn.org> <20171113032640.tbn7icsllm6jeeny@mx4.yitter.info> <5A09C4D6.6080202@redbarn.org> <20171114063209.gjubqyovnwcrl33a@mx4.yitter.info> <5A0A952F.1060001@redbarn.org> <20171114080638.GA41253@isc.org> <5A0AA777.9010908@redbarn.org> <20171114175300.GA45323@isc.org> <23051.41140.187552.962508@gro.dd.org> <5A0BB7B5.8050804@redbarn.org>
User-Agent: Alpine 2.11 (DEB 23 2013-08-11)
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset="US-ASCII"
Archived-At: <https://mailarchive.ietf.org/arch/msg/dnsop/MEXmMBmzozmpIhTJKeUr4Ap96Lg>
Subject: Re: [DNSOP] Clarifying referrals (#35)
X-BeenThere: dnsop@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dnsop>, <mailto:dnsop-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dnsop/>
List-Post: <mailto:dnsop@ietf.org>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dnsop>, <mailto:dnsop-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 15 Nov 2017 12:18:31 -0000

Paul Vixie <paul@redbarn.org> wrote:
>
> the reason i use SERVFAIL for NOTAUTH is because what i want the initiator to
> do when i'm configured as primary but can't read my zone file, or am
> configured as secondary but can't write my zone file, is the same as what i
> want when i'm not configured for the zone: cache this failure under a
> hold-down timer so as not to melt the tubez, but do try again later in case
> i'm merely late to change my config, or flubbed my config in some way.

I'm interested in this discussion.

Recently I changed private.cam.ac.uk so that queries from off-campus get
NXDOMAIN instead of REFUSED. This had the unanticipated effect of halving
the query load on our authoritative servers. Not really surprising except
perhaps for the size of the effect.

I've had a skim through BIND's resolver code to see how the lame server
cache works. It's, um, not simple :-) but as far as I can see, both
SERVFAIL and REFUSED responses get the server put in the lame cache.

(BIND's servfail cache is different - that's for failures of this server
itself, not the servers it is sending queries to.)

Tony.
-- 
f.anthony.n.finch  <dot@dotat.at>  http://dotat.at/  -  I xn--zr8h punycode
Fisher, German Bight: Northwest backing south 4 or 5, veering southwest 5 to 7
later. Moderate, occasionally rough. Showers. Moderate or good.