Re: [DNSOP] draft-ietf-dnsop-rfc6598-rfc6303-01

Evan Hunt <each@isc.org> Thu, 21 August 2014 03:28 UTC

Return-Path: <each@isc.org>
X-Original-To: dnsop@ietfa.amsl.com
Delivered-To: dnsop@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 0239D1A6F6D for <dnsop@ietfa.amsl.com>; Wed, 20 Aug 2014 20:28:51 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.569
X-Spam-Level:
X-Spam-Status: No, score=-2.569 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RP_MATCHES_RCVD=-0.668, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id pENqlCyRClCU for <dnsop@ietfa.amsl.com>; Wed, 20 Aug 2014 20:28:49 -0700 (PDT)
Received: from mx.pao1.isc.org (mx.pao1.isc.org [IPv6:2001:4f8:0:2::2b]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id DA21F1A6F54 for <dnsop@ietf.org>; Wed, 20 Aug 2014 20:28:49 -0700 (PDT)
Received: from bikeshed.isc.org (bikeshed.isc.org [IPv6:2001:4f8:3:d::19]) (using TLSv1 with cipher DHE-RSA-CAMELLIA256-SHA (256/256 bits)) (Client CN "mail.isc.org", Issuer "RapidSSL CA" (not verified)) by mx.pao1.isc.org (Postfix) with ESMTPS id D89E33493A2; Thu, 21 Aug 2014 03:28:48 +0000 (UTC)
Received: by bikeshed.isc.org (Postfix, from userid 10292) id C71F9216C3B; Thu, 21 Aug 2014 03:28:48 +0000 (UTC)
Date: Thu, 21 Aug 2014 03:28:48 +0000
From: Evan Hunt <each@isc.org>
To: Mark Andrews <marka@isc.org>
Message-ID: <20140821032848.GA41127@isc.org>
References: <7EA38D42-3915-403E-AFE3-C0A8E4A391BF@hopcount.ca> <Prayer.1.3.5.1408201750020.12368@hermes-1.csi.cam.ac.uk> <19AE3CB3-B108-42CB-BAE2-A2F1FBB55EF4@hopcount.ca> <20140820214845.70AEA1D1A20E@rock.dv.isc.org> <E4AD7D21-995C-46B1-813E-70CA0919F6CE@hopcount.ca> <20140820235118.E952B1D1B042@rock.dv.isc.org> <20140821005246.E3C7D1D1B8C8@rock.dv.isc.org> <20140821012100.GC2837@mx1.yitter.info> <54885A5D-2AFA-4D37-9B83-2229082D7BA4@virtualized.org> <20140821021725.AE52C1D1BF39@rock.dv.isc.org>
Mime-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Disposition: inline
In-Reply-To: <20140821021725.AE52C1D1BF39@rock.dv.isc.org>
User-Agent: Mutt/1.4.2.3i
Archived-At: http://mailarchive.ietf.org/arch/msg/dnsop/P2OZZ5hTXsk4reybryvDa4da8Ag
Cc: dnsop@ietf.org, David Conrad <drc@virtualized.org>, Andrew Sullivan <ajs@anvilwalrusden.com>
Subject: Re: [DNSOP] draft-ietf-dnsop-rfc6598-rfc6303-01
X-BeenThere: dnsop@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dnsop>, <mailto:dnsop-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/dnsop/>
List-Post: <mailto:dnsop@ietf.org>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dnsop>, <mailto:dnsop-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 21 Aug 2014 03:28:51 -0000

On Thu, Aug 21, 2014 at 12:17:25PM +1000, Mark Andrews wrote:
> If they fail it can
> fallback to making iterative queries or just accept the failure.

I'd quibble with this bit: if it can make iterative queries, then we
might as well just call it a validating resolver.

IMHO the thing we're describing is an application that gets DNS service
from a recursive resolver, but validates the answers rather than trusting
them implicitly.  It needs to be able to send the resolver a succession of
queries to obtain the chain of trust, but it's not going to be iterating
down from the root.

The "delv" utility that ships with BIND 9.10 is an example.

-- 
Evan Hunt -- each@isc.org
Internet Systems Consortium, Inc.