Re: [DNSOP] Adoption of new EDNS opcode "rrserial"

Tony Finch <dot@dotat.at> Mon, 10 May 2021 21:09 UTC

Return-Path: <fanf2@hermes.cam.ac.uk>
X-Original-To: dnsop@ietfa.amsl.com
Delivered-To: dnsop@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id C29FB3A2B37 for <dnsop@ietfa.amsl.com>; Mon, 10 May 2021 14:09:57 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.648
X-Spam-Level:
X-Spam-Status: No, score=-1.648 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HEADER_FROM_DIFFERENT_DOMAINS=0.249, RCVD_IN_DNSWL_BLOCKED=0.001, RCVD_IN_MSPIKE_H4=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=no autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id YAPZWcmFHWqB for <dnsop@ietfa.amsl.com>; Mon, 10 May 2021 14:09:53 -0700 (PDT)
Received: from ppsw-32.csi.cam.ac.uk (ppsw-32.csi.cam.ac.uk [131.111.8.132]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 2B61F3A2B31 for <dnsop@ietf.org>; Mon, 10 May 2021 14:09:52 -0700 (PDT)
X-Cam-AntiVirus: no malware found
X-Cam-ScannerInfo: http://help.uis.cam.ac.uk/email-scanner-virus
Received: from [90.251.241.247] (port=62978 helo=milebook.lan) by ppsw-32.csi.cam.ac.uk (smtp.hermes.cam.ac.uk [131.111.8.156]:25) with esmtpsa (PLAIN:fanf2) (TLS1.2:ECDHE-RSA-AES256-GCM-SHA384:256) id 1lgD9y-000h08-0b (Exim 4.94.2) (return-path <fanf2@hermes.cam.ac.uk>); Mon, 10 May 2021 22:09:50 +0100
Date: Mon, 10 May 2021 22:09:49 +0100
From: Tony Finch <dot@dotat.at>
To: Peter van Dijk <peter.van.dijk@powerdns.com>
cc: dnsop@ietf.org
In-Reply-To: <6d121251eb229ff2e0650da05d447bacc94c2c31.camel@powerdns.com>
Message-ID: <328e8ade-e95b-2d1f-70c6-04d28ffb74b@dotat.at>
References: <20200127150847.taxhqeipwq6jg2rr@nic.cl> <CAAk_VVivs96dL-qVw8rqSXjkukBFHPyr2htWApbb44SVyQsGag@mail.gmail.com> <20210507164749.GC91746@pepino> <20210510163716.GC5718@pepino> <6d121251eb229ff2e0650da05d447bacc94c2c31.camel@powerdns.com>
MIME-Version: 1.0
Content-Type: text/plain; charset="US-ASCII"
Sender: Tony Finch <fanf2@hermes.cam.ac.uk>
Archived-At: <https://mailarchive.ietf.org/arch/msg/dnsop/Tsc79hZp-uDzr7dWtkYsdFsOrR8>
Subject: Re: [DNSOP] Adoption of new EDNS opcode "rrserial"
X-BeenThere: dnsop@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dnsop>, <mailto:dnsop-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dnsop/>
List-Post: <mailto:dnsop@ietf.org>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dnsop>, <mailto:dnsop-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 10 May 2021 21:10:00 -0000

Peter van Dijk <peter.van.dijk@powerdns.com> wrote:
>
> Also in section 3.2, I do not think responding with the option should
> be limited to NOERROR. Specifically, I'd very much also want it to work
> for NXDOMAIN,

Isn't the SOA record usually present in a negative response?

> and I can imagine some cases of it being useful even in SERVFAIL cases
> (at least in database-driven name servers like PowerDNS, where
> individual records inside a zone can be broken).

Perhaps also in cases where the server has a copy of zone serial number
NNN but it has expired.

Tony.
-- 
f.anthony.n.finch  <dot@dotat.at>  https://dotat.at/
Viking, North Utsire: Cyclonic 6 to gale 8, becoming southerly 3 to 5.
Moderate or rough, becoming moderate in North Utsire. Rain, fog
patches. Moderate or good, occasionally very poor.