[DNSOP] Re: [v6ops] Re: Re: Moving DNS64 (RFC6147) to Internet Standard

"jordi.palet@consulintel.es" <jordi.palet@consulintel.es> Sat, 11 April 2026 08:05 UTC

Return-Path: <prvs=1561945371=jordi.palet@consulintel.es>
X-Original-To: dnsop@mail2.ietf.org
Delivered-To: dnsop@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id E7282DA451B3 for <dnsop@mail2.ietf.org>; Sat, 11 Apr 2026 01:05:02 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1775894702; bh=piS48DU6QHXWR4CV63Ai5nKI7J79BJhDpkd26Ts58hE=; h=From:Subject:Date:References:To:In-Reply-To; b=ltM5g5+dsO108Yht5RGOSFnOm1YTuqp7EXNXHhYugKGY1Pe6wf4BTslvVcKFhO6ss +uKV4CUe3b6mQSjDoCaVUUpeNOUwz2xOiMNGZVYR990opeZtrmLYqT5AxBNjgsM5zi v/FSCv0tMm/hxXBoeJfxSEVGB2P1j9D7V4GeomJk=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -1.999
X-Spam-Level:
X-Spam-Status: No, score=-1.999 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=consulintel.es
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Mns1GiHM-50l for <dnsop@mail2.ietf.org>; Sat, 11 Apr 2026 01:05:01 -0700 (PDT)
Received: from mail.consulintel.es (mail.consulintel.es [IPv6:2001:470:1f09:495::5]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 896C8DA45103 for <dnsop@ietf.org>; Sat, 11 Apr 2026 01:04:17 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=consulintel.es; s=mailer; t=1775894657; x=1776499457; i=jordi.palet@consulintel.es; q=dns/txt; h=From:Content-Type: Content-Transfer-Encoding:Mime-Version:Subject:Date:References: To:In-Reply-To:Message-Id; bh=z6TBKuJwuf3kABgat6pIADY18v0V7nbc02 oe+hh+bfE=; b=eM28LOvEUVhVcYp1HhAQwQPFdtGSHu2F6QKHNCQDS6ExU6NU1r PG4lCx66a2AdVCPg+N1cTjj6AuBmnqx86r9so3BdevLBTStZrRzm+cFQSDoBYKQg i6tU9NljO3KNdSYaO1VHdal1KCY9CS+qFaGjXIWOr7uqGR+sF91Bof5P2K1DlKf/ cor/SUnxZ5l+0hu/3cflp+a6ychq5RuSjx05Dfy4ImyR72Yzl/TNx1g0YgPIQsbU 0o8YUA2wIQE3Sk1pPGQ9XW5Kis8U7sEcj429EfpWmT/jGqGdiFvBFgY+/uxbyhkW piR/cj1CxD9Zlgzo/e1/n7IMjql/gpiZPbIw==
X-MDAV-Processed: mail.consulintel.es, Sat, 11 Apr 2026 10:04:16 +0200 (not processed: message from trusted source)
X-Spam-Processed: mail.consulintel.es, Sat, 11 Apr 2026 10:04:16 +0200
Received: from smtpclient.apple by mail.consulintel.es (10.10.10.5) (MDaemon PRO v25.5.0) with ESMTPSA id md5001002618762.msg; Sat, 11 Apr 2026 10:04:16 +0200
X-MDRemoteIP: 2001:470:1f09:495:c5db:75f:ddd9:542e
X-MDArrival-Date: Sat, 11 Apr 2026 10:04:16 +0200
X-Authenticated-Sender: jordi.palet@consulintel.es
X-Return-Path: prvs=1561945371=jordi.palet@consulintel.es
X-Envelope-From: jordi.palet@consulintel.es
X-MDaemon-Deliver-To: dnsop@ietf.org
From: "jordi.palet@consulintel.es" <jordi.palet@consulintel.es>
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: quoted-printable
Mime-Version: 1.0 (Mac OS X Mail 16.0 \(3864.500.181\))
Date: Sat, 11 Apr 2026 10:04:01 +0200
References: <m1wAunU-0000NEC@stereo.hq.phicoh.net> <2338256.t9SDvczpPo@localhost> <038ae9d1-34fc-4085-aa6d-76ef79287857@gmail.com> <m1wB6Wn-0000NiC@stereo.hq.phicoh.net>
To: dnsop@ietf.org
In-Reply-To: <m1wB6Wn-0000NiC@stereo.hq.phicoh.net>
Message-Id: <20DC98A0-F167-4490-AFA0-A016EC5022D3@consulintel.es>
X-Mailer: Apple Mail (2.3864.500.181)
X-MDCFSigsAdded: consulintel.es
Message-ID-Hash: 2Q5CUGFDPUBI4IJFB2OWONU2XKL2E7RY
X-Message-ID-Hash: 2Q5CUGFDPUBI4IJFB2OWONU2XKL2E7RY
X-MailFrom: prvs=1561945371=jordi.palet@consulintel.es
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-dnsop.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [DNSOP] Re: [v6ops] Re: Re: Moving DNS64 (RFC6147) to Internet Standard
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/dnsop/TME-PkpdA1zUoUCoYP2NEmGrDE8>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dnsop>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Owner: <mailto:dnsop-owner@ietf.org>
List-Post: <mailto:dnsop@ietf.org>
List-Subscribe: <mailto:dnsop-join@ietf.org>
List-Unsubscribe: <mailto:dnsop-leave@ietf.org>

Let me repeat this.

The discovery is not in RFC6147, but RFC7050. This involved some security issues fixed by RFC8880.

In my experience this discovery mechanism is not being actually used (if anyone has a different experience I will be very happy to hear). So I will actually advocate for deprecating RFC7050, or at least not recommend its use anymore in favor of PREF64 (RFC8181) and PCP (RFC7225).

Regards,
Jordi

@jordipalet


> El 10 abr 2026, a las 9:43, Philip Homburg <pch-dnsop-7@u-1.phicoh.com> escribió:
> 
>> I'm very torn on that, because like it or not DNS64 is stable,
>> well-defined, and widely implemented. (I'd also prefer to abolish
>> the problem by abolishing the distinction between Proposed Standard
>> and Internet Standard, but that's another story.)
>> 
>> But we still do need co-existence for very practical reasons. That's
>> why v6ops is developing the IPv6-mostly approach in draft-ietf-v6ops-6mops,
>> which explicitly says:  "Those concerns make DNS64 a suboptimal
>> and undesirable solution long-term.  To eliminate the needs for
>> DNS64..." etc.
> 
> What do we gain by advancing DNS64? It seems that draft-ietf-v6ops-6mops
> uses DNS64 mainly for discovery of the translation prefix. If DNS64 would be
> scoped such that it only works for ipv4only.arpa. then there is not a lot
> of harm in having that as part of a DNS resolver.
> 
> Having a full DNS64 component only for the purpose of discovering the
> translation prefix is likely to do more harm than good.
> 
> _______________________________________________
> DNSOP mailing list -- dnsop@ietf.org
> To unsubscribe send an email to dnsop-leave@ietf.org


**********************************************
IPv4 is over
Are you ready for the new Internet ?
http://www.theipv6company.com
The IPv6 Company

This electronic message contains information which may be privileged or confidential. The information is intended to be for the exclusive use of the individual(s) named above and further non-explicilty authorized disclosure, copying, distribution or use of the contents of this information, even if partially, including attached files, is strictly prohibited and will be considered a criminal offense. If you are not the intended recipient be aware that any disclosure, copying, distribution or use of the contents of this information, even if partially, including attached files, is strictly prohibited, will be considered a criminal offense, so you must reply to the original sender to inform about this communication and delete it.