Re: [DNSOP] New Version Notification for draft-pusateri-dnsop-update-timeout-00.txt
Ted Lemon <mellon@fugue.com> Sat, 25 August 2018 18:14 UTC
Return-Path: <mellon@fugue.com>
X-Original-To: dnsop@ietfa.amsl.com
Delivered-To: dnsop@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id AEC50130E10 for <dnsop@ietfa.amsl.com>; Sat, 25 Aug 2018 11:14:24 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.909
X-Spam-Level:
X-Spam-Status: No, score=-1.909 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001, T_DKIMWL_WL_MED=-0.01, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=fugue-com.20150623.gappssmtp.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id vUjX0iq1TF4K for <dnsop@ietfa.amsl.com>; Sat, 25 Aug 2018 11:14:21 -0700 (PDT)
Received: from mail-io0-x22d.google.com (mail-io0-x22d.google.com [IPv6:2607:f8b0:4001:c06::22d]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 14973127333 for <dnsop@ietf.org>; Sat, 25 Aug 2018 11:14:21 -0700 (PDT)
Received: by mail-io0-x22d.google.com with SMTP id r196-v6so9669517iod.0 for <dnsop@ietf.org>; Sat, 25 Aug 2018 11:14:21 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=fugue-com.20150623.gappssmtp.com; s=20150623; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=md95WJ29ZBAtLPbkNlBj1KFjWe0Tt8CItJF4Hv8Prmo=; b=pw926TfUFIY79zZP75PpHoa0939K9km9vunGtAEHTZGnoidOAq8EiLqPvAmZ4ZTkwI C0BSTKnGO3FmfT2f5sOoPcWyFVL4W0soBd4m8HNSwCzDOoAQGZIGSnkaC0ShlDjBurE9 aqGtB5KDFuAVWaRMIbwPmWZPfIZ+ochoFxMqCGRaNn8wXv0+i/ooTV3WejkmTbPGMx7r skVxMtWAFQLkAvTiYLGWv865ivnRANg/Bi/5cTEtmDZiW9huKs9z0AaSjsh4o40wRnXp F4utEF7cqmlPMQCvn01g6JaIMPJoy5jypCNFYVa04hjQC8KTNVfZ85MOZUA+d2JquHMj nHaA==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=md95WJ29ZBAtLPbkNlBj1KFjWe0Tt8CItJF4Hv8Prmo=; b=kxMRFSI4/+ds0BefpvLXaPIUAYGeemGi2yo2HdhHndXI4OmRFSwLXP4GEYLekt536q kxx1TPRHfhnyXOOtj3Le5ELiY1NggS1A2/T6z7Qx6LVE76UEiCfM+IrDpY3B8ZqWEHUp RZZuejHdL9UJUDSFV1xGd7Z//pR81SRKBVJ2jRxiOldBuc65s/WcQRib2XQay9rvrveb DUaVG6qD/6egR1rVRS9x2OShVKimOgBwHwo4ziRsO8pk7YuI+nyCzkM/NdLsyd+gZA1p QwytUegHDjuYrIwLU0hwDrK4efyEfHVw9FBuiPKsmYqweI+CLyB20PmsL8lr6wxE5Oba lAEw==
X-Gm-Message-State: APzg51Dd3aWcZszole6NCCKQhbiORCND1Mco4y6Bq9unaz82Z7GlzIFO Nxawn0op9ys6sallmIKVWQWk4vuH9F9QiZibC32XSgPC
X-Google-Smtp-Source: ANB0VdYxZ/ywReW2uqQJRfQPiD2ja78nZpoCz9DSKCgpZIpq3MyuyT7wQDTdjTgdJ315qnol08Am51GxxECbXkS6K28=
X-Received: by 2002:a6b:dd01:: with SMTP id f1-v6mr5167673ioc.45.1535220860277; Sat, 25 Aug 2018 11:14:20 -0700 (PDT)
MIME-Version: 1.0
References: <153507165910.12116.7113196606839876181.idtracker@ietfa.amsl.com> <AFB90F6F-5D99-4403-AAB6-1123727973E6@bangj.com> <5B7F5E07.5080100@redbarn.org> <7F91FFF7-71C3-4F8E-82CD-266B170983E0@bangj.com> <C0EE2719-B662-4231-AF51-D3B98B00AD0D@fugue.com> <6D607922-393D-4549-AAFA-49279C260CA4@bangj.com> <3C6100BD-62D6-41ED-B7BF-679F0D4E4113@fugue.com> <5063A32B-4877-4860-BA73-CCB068AB7FCB@bangj.com> <CAPt1N1=tXZNgT6ygAaLFfOMze7hbGZ6q_eN1C3iEo9ryBNcyLg@mail.gmail.com> <98EF2CAC-7C13-4E68-8D2B-EC0659EA9646@bangj.com> <CAPt1N1kFNY4=CUMsTvXmeRREeLAkY8xpBdw4vPDxujgke6QT8A@mail.gmail.com> <963460AA-14BB-44AA-87CA-7F09A707DB5D@bangj.com> <47AE41F8-9F5F-4CC8-B4F0-7E8191011E99@bangj.com> <F4335D3A-0241-437F-A428-8EA95F0A1C18@fugue.com> <56E8B2A6-7B65-4D25-B102-9EFA7E2CBE7B@bangj.com> <86D465A4-F390-4370-83EC-0E72FBE115BE@isc.org> <CAPt1N1=xy+JAtgvvF_+9LiTiefbpTy_Vd0b8gswozA1K1C57Nw@mail.gmail.com> <99FA0B76-D225-45FC-A33C-B65E2673A45E@isc.org> <CAPt1N1kp8Tg5tWEiDCMuMNTmehRsBSkkC1=u+RcvkG6ZCegE-g@mail.gmail.com> <977DF12E-178B-4500-B045-F27BF1CDF51C@isc.org> <CAPt1N1=cafnVmnNM2eSF67QbgRk8hUEAd2Gwuqx4OUehPZSmyQ@mail.gmail.com> <AC3FE6CF-CC11-44D3-8C50-BC19C295F001@bangj.com>
In-Reply-To: <AC3FE6CF-CC11-44D3-8C50-BC19C295F001@bangj.com>
From: Ted Lemon <mellon@fugue.com>
Date: Sat, 25 Aug 2018 14:13:43 -0400
Message-ID: <CAPt1N1ksyp1t_e9Qd4FTtTVsZr9+VDm11MR-jS9Oz8Kpz7J7AQ@mail.gmail.com>
To: Tom Pusateri <pusateri@bangj.com>
Cc: Mark Andrews <marka@isc.org>, dnsop WG <dnsop@ietf.org>
Content-Type: multipart/alternative; boundary="000000000000078f0f05744676f1"
Archived-At: <https://mailarchive.ietf.org/arch/msg/dnsop/PbzZNh3rV8VQ587Rmk_n7_GFR2A>
Subject: Re: [DNSOP] New Version Notification for draft-pusateri-dnsop-update-timeout-00.txt
X-BeenThere: dnsop@ietf.org
X-Mailman-Version: 2.1.27
Precedence: list
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dnsop>, <mailto:dnsop-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dnsop/>
List-Post: <mailto:dnsop@ietf.org>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dnsop>, <mailto:dnsop-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sat, 25 Aug 2018 18:14:25 -0000
Well, okay, but isn't this just for garbage collection? Why is it a problem if the garbage collection is delayed? If the primary is down, it's not like some other device could claim that name anyway. On Sat, Aug 25, 2018 at 2:11 PM Tom Pusateri <pusateri@bangj.com> wrote: > This is a valid question. > > In most cases, having the primary remember the lease lifetime should be > enough. But if the outage is longer than the lease lifetime, it would > better if the secondary would also have that information. > > But more importantly, the primary has to store the lease lifetimes for > it’s own use for protection against restarts, reboots, and crashes. Keeping > the lease lifetime closest to the records they reference is a good > principle and so storing them as records along with the records they > reference seems not only reasonable, but preferred. > > Whether or not they are transferred to the secondary is of secondary > importance. But having them treated as regular records has been recommended > so having them transferred during AXFR/IXFR will be looked upon with favor. > > Thanks, > Tom > > > > On Aug 25, 2018, at 11:11 AM, Ted Lemon <mellon@fugue.com> wrote: > > Right; my question is, is this an operational problem people are having > IRL? If it is, then it makes sense to do something about it. If it's > not, it doesn't. I've never seen people do what you're describing in > practice; that's why I'm asking. And we definitely agree that there needs > to be a cleanup process; the question is, does it have to be done this > way. E.g., if the lease isn't part of the zone, is that actually a > problem? Does the lease *need* to be part of the zone transfer, or is > it enough that the primary has it? For my part, it seems unnecessary for > the secondaries to have it, since they can't update the zone anyway. As > long as the primary remembers that there's a lease, the right thing will > happen. > > On Sat, Aug 25, 2018 at 10:30 AM Mark Andrews <marka@isc.org> wrote: > >> It avoids leaving dangling records published longer than necessary. >> >> Network dies so the machine can’t do the cleanup it was intending. >> >> Last second cleanup as the lid closes doesn’t get through. >> >> It’s relatively easy to implement, no more difficult than resigning for >> DNSSEC at the cost of a small amount of space. It also transfers the >> necessary state to all the slaves allowing them to take over if the master >> server fails presuming they have the keying material for DNSSEC. >> >> -- >> Mark Andrews >> >> On 25 Aug 2018, at 22:53, Ted Lemon <mellon@fugue.com> wrote: >> >> I'm not saying nobody does it. I'm trying to understand how this helps. >> >> On Fri, Aug 24, 2018 at 11:24 PM Mark Andrews <marka@isc.org> wrote: >> >>> Ted stop being daft. People have been registering addresses of machines >>> in the public DNS for decades. SLAAC. Is just one source of addresses. >>> DHCP is another. Come up with a third method and they will do it with it. >>> >>> Also DHCP servers from ISPs don’t have authority to update DNS servers >>> for my machines. Only those machines have such authority so don’t discount >>> DHCP derived addresses. >>> >>> -- >>> Mark Andrews >>> >>> On 25 Aug 2018, at 12:53, Ted Lemon <mellon@fugue.com> wrote: >>> >>> When would that happen? >>> >>> On Fri, Aug 24, 2018 at 10:52 PM Mark Andrews <marka@isc.org> wrote: >>> >>>> Registering slaac derived addresses in the DNS. These are tied to >>>> prefix lifetimes. >>>> >>>> >>>> -- >>>> Mark Andrews >>>> >>>> On 25 Aug 2018, at 05:02, Tom Pusateri <pusateri@bangj.com> wrote: >>>> >>>> >>>> >>>> On Aug 24, 2018, at 2:59 PM, Ted Lemon <mellon@fugue.com> wrote: >>>> >>>> On Aug 24, 2018, at 2:43 PM, Tom Pusateri <pusateri@bangj.com> wrote: >>>> >>>> It seems odd to take the position that the authoritative server >>>> shouldn’t need to clean up stale entries because it assumes the client will >>>> do it for you. I can’t imagine you taking this position under any other >>>> scenario. >>>> >>>> >>>> The issue here is that this is a pretty major change to the DNS. If >>>> we really want something this heavy, we should have a good reason for >>>> wanting it. That's all. >>>> >>>> The idea that some unnamed DHCP server somewhere doesn't do the right >>>> thing with cleaning up stale entries doesn't seem like a good enough >>>> reason, particularly given that the DHCID record tags the thing as having >>>> been added by the DHCP server, and considering that there are several open >>>> source implementations that do automatically delete records when the lease >>>> expires. >>>> >>>> I think it might make sense to just wait on this. I agree that it's an >>>> interesting idea for completeness, but we don't have enough operational >>>> experience yet to know whether we have a problem worth solving. With >>>> respect to the DHCP use case, I'm certain we don't. >>>> >>>> The good news is that if we do need this, you've done a design, and we >>>> also have Paul's design to look at. So if operational experience a few >>>> years down the road shows us that we have a gap here, we can move on it >>>> pretty easily. I just don't see any reason to rush into it. >>>> >>>> >>>> Ok, great. Hopefully others have some use cases they can share. In the >>>> mean time, back to learning Rust… >>>> >>>> Thanks, >>>> Tom >>>> >>>> _______________________________________________ >>>> DNSOP mailing list >>>> DNSOP@ietf.org >>>> https://www.ietf.org/mailman/listinfo/dnsop >>>> >>>> >
- [DNSOP] Fwd: New Version Notification for draft-p… Tom Pusateri
- Re: [DNSOP] Fwd: New Version Notification for dra… Paul Vixie
- Re: [DNSOP] Fwd: New Version Notification for dra… Tom Pusateri
- Re: [DNSOP] New Version Notification for draft-pu… Tom Pusateri
- Re: [DNSOP] New Version Notification for draft-pu… Paul Vixie
- Re: [DNSOP] New Version Notification for draft-pu… Mark Andrews
- Re: [DNSOP] New Version Notification for draft-pu… Paul Vixie
- Re: [DNSOP] Fwd: New Version Notification for dra… Mark Andrews
- Re: [DNSOP] Fwd: New Version Notification for dra… Ted Lemon
- Re: [DNSOP] Fwd: New Version Notification for dra… Ted Lemon
- Re: [DNSOP] Fwd: New Version Notification for dra… Tom Pusateri
- Re: [DNSOP] Fwd: New Version Notification for dra… Ted Lemon
- Re: [DNSOP] Fwd: New Version Notification for dra… Joe Abley
- Re: [DNSOP] Fwd: New Version Notification for dra… Tom Pusateri
- Re: [DNSOP] Fwd: New Version Notification for dra… Tom Pusateri
- Re: [DNSOP] Fwd: New Version Notification for dra… Ted Lemon
- Re: [DNSOP] New Version Notification for draft-pu… Tom Pusateri
- Re: [DNSOP] New Version Notification for draft-pu… Ted Lemon
- Re: [DNSOP] New Version Notification for draft-pu… Tom Pusateri
- Re: [DNSOP] New Version Notification for draft-pu… Tom Pusateri
- Re: [DNSOP] New Version Notification for draft-pu… Ted Lemon
- Re: [DNSOP] New Version Notification for draft-pu… Tom Pusateri
- Re: [DNSOP] New Version Notification for draft-pu… Mark Andrews
- Re: [DNSOP] New Version Notification for draft-pu… Ted Lemon
- Re: [DNSOP] New Version Notification for draft-pu… Mark Andrews
- Re: [DNSOP] New Version Notification for draft-pu… Tom Pusateri
- Re: [DNSOP] New Version Notification for draft-pu… Tom Pusateri
- Re: [DNSOP] New Version Notification for draft-pu… Mark Andrews
- Re: [DNSOP] New Version Notification for draft-pu… Ted Lemon
- Re: [DNSOP] New Version Notification for draft-pu… Mark Andrews
- Re: [DNSOP] New Version Notification for draft-pu… Ted Lemon
- Re: [DNSOP] New Version Notification for draft-pu… Paul Vixie
- Re: [DNSOP] New Version Notification for draft-pu… Tom Pusateri
- Re: [DNSOP] New Version Notification for draft-pu… Ted Lemon
- Re: [DNSOP] New Version Notification for draft-pu… Paul Vixie
- Re: [DNSOP] New Version Notification for draft-pu… Tom Pusateri
- Re: [DNSOP] New Version Notification for draft-pu… Tom Pusateri
- Re: [DNSOP] New Version Notification for draft-pu… John Levine
- Re: [DNSOP] New Version Notification for draft-pu… Ted Lemon
- Re: [DNSOP] New Version Notification for draft-pu… Tom Pusateri
- Re: [DNSOP] New Version Notification for draft-pu… Tom Pusateri
- Re: [DNSOP] New Version Notification for draft-pu… Ted Lemon
- Re: [DNSOP] New Version Notification for draft-pu… Ted Lemon
- Re: [DNSOP] New Version Notification for draft-pu… Paul Vixie
- Re: [DNSOP] New Version Notification for draft-pu… Tom Pusateri
- Re: [DNSOP] New Version Notification for draft-pu… Tom Pusateri
- Re: [DNSOP] New Version Notification for draft-pu… Paul Vixie
- Re: [DNSOP] New Version Notification for draft-pu… Tom Pusateri
- Re: [DNSOP] New Version Notification for draft-pu… Paul Vixie
- Re: [DNSOP] New Version Notification for draft-pu… Tom Pusateri
- Re: [DNSOP] New Version Notification for draft-pu… Ted Lemon
- Re: [DNSOP] New Version Notification for draft-pu… Tom Pusateri
- Re: [DNSOP] New Version Notification for draft-pu… Tom Pusateri
- Re: [DNSOP] New Version Notification for draft-pu… Ted Lemon
- Re: [DNSOP] New Version Notification for draft-pu… Mark Andrews
- Re: [DNSOP] New Version Notification for draft-pu… Ted Lemon
- Re: [DNSOP] New Version Notification for draft-pu… Mark Andrews
- Re: [DNSOP] New Version Notification for draft-pu… Tom Pusateri
- Re: [DNSOP] New Version Notification for draft-pu… Tom Pusateri
- Re: [DNSOP] New Version Notification for draft-pu… Tom Pusateri
- Re: [DNSOP] New Version Notification for draft-pu… Tom Pusateri
- Re: [DNSOP] New Version Notification for draft-pu… Ted Lemon
- Re: [DNSOP] New Version Notification for draft-pu… Tom Pusateri
- Re: [DNSOP] New Version Notification for draft-pu… Ted Lemon
- Re: [DNSOP] New Version Notification for draft-pu… Mark Andrews
- Re: [DNSOP] New Version Notification for draft-pu… Ted Lemon
- Re: [DNSOP] New Version Notification for draft-pu… Mark Andrews
- Re: [DNSOP] New Version Notification for draft-pu… Mark Andrews
- Re: [DNSOP] New Version Notification for draft-pu… Mark Andrews
- Re: [DNSOP] New Version Notification for draft-pu… Mark Andrews
- Re: [DNSOP] New Version Notification for draft-pu… Tom Pusateri