Re: [DNSOP] abandoning ANAME and standardizing CNAME at apex

Shumon Huque <shuque@gmail.com> Fri, 22 June 2018 19:51 UTC

Return-Path: <shuque@gmail.com>
X-Original-To: dnsop@ietfa.amsl.com
Delivered-To: dnsop@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 4CFF5130DF5 for <dnsop@ietfa.amsl.com>; Fri, 22 Jun 2018 12:51:43 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.999
X-Spam-Level:
X-Spam-Status: No, score=-1.999 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 3xHFO5gcORYX for <dnsop@ietfa.amsl.com>; Fri, 22 Jun 2018 12:51:37 -0700 (PDT)
Received: from mail-yb0-x236.google.com (mail-yb0-x236.google.com [IPv6:2607:f8b0:4002:c09::236]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id C6212130EE0 for <dnsop@ietf.org>; Fri, 22 Jun 2018 12:51:37 -0700 (PDT)
Received: by mail-yb0-x236.google.com with SMTP id a16-v6so2972922ybm.2 for <dnsop@ietf.org>; Fri, 22 Jun 2018 12:51:37 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=ntsFZgoR3bySimsFJkUr66z0vfncFEg3GwaXfTjnheU=; b=U6rMJE1e1vfaXnsfI1J4qxDROFtA6NU7ZC9O/7TGcTGHKcACklvFpwgFteRXHV/AOL G5XYR0aN5UG8NKtuIgYUZfj5kgmtRoul+zFum98hTDIsypJ53GpJRxhv8XfLzfDG7j/Q rlYKhW8NybLrseZNClCDDI3b1Urgiva8z39CmRG4jrReB6bUmulv4hfIBNA5Z1tIs+hd ip3mHosODrwK0zjTv33TuZhodsRfK+Jx/z8K5BvpJ+eGbg29TvqNTQUxqV/GVlhdsopk 84Gmp1ErRkrkVrf9JUDu1uWGq9j1FdRFRGY8ig8sYnEj+AmX4TGptVRjuThVvvSQ5C91 NchQ==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=ntsFZgoR3bySimsFJkUr66z0vfncFEg3GwaXfTjnheU=; b=HsttBqh2juBeTqRtYs++TUmSW1Dv9/wYB9bMIFZEFa4Ffi5+VA2EjcivBpm1FhSl5r u4SL7/4kZMGUBTeknrhdny5W/4ZA9gNC6PDeK2g0tia3w1lLj+gRC1f2VzdGjC7cR9l0 hwT8Zqvr2b1yG86n/T7JZLDBAQzk/GfhRSZaS7insOYRggXC3Z4CPwh8pwsaTaEWwQuX dcu6rEgKZRru1G4dnrSFZFhP7SoxW5gDmi5816syE0zBGBUuukkSwNAEUXKZt+Lb/pj6 vOwERGejRGEsuZUdTeBVgV/TiwBiXdcEfTO+Q3tGmMXuoKMq2zKHCAzKkw/45V54QnCi IphA==
X-Gm-Message-State: APt69E1N6PATyX5W9EJIHraSJgJJkQ6K7yN7bQv9A+kE5QJ/rwtvaDzI EMlgxGSvYgZXFNf/pfLVO46rMmbjnnCVZE+8X3Y=
X-Google-Smtp-Source: ADUXVKLFC78LiaJPaD9lt3ob+H2ZzX5JOdfScHmmxxmin+/eN0PnVUEASqhUEO2p+EpWyb/DKWuHkdhjGlIvNd1PHQ8=
X-Received: by 2002:a25:1289:: with SMTP id 131-v6mr1618085ybs.171.1529697097087; Fri, 22 Jun 2018 12:51:37 -0700 (PDT)
MIME-Version: 1.0
References: <b73f3dc7-b378-d5d8-c7a2-42bc4326fbae@nic.cz> <alpine.DEB.2.11.1806191428250.916@grey.csi.cam.ac.uk> <691FC45D-E5B6-4131-95BF-878520351F3A@gmail.com> <bf0ba568-1a18-f8cf-c1a0-3f547d642a78@bellis.me.uk> <0438207E-A4C2-434D-9507-9D9F54765CFB@puck.nether.net> <alpine.DEB.2.11.1806191649350.916@grey.csi.cam.ac.uk> <9a0d1bae-dc58-99b5-40d1-caa7737dbfb1@bellis.me.uk> <1B7B2BB4-F0AE-4188-B89B-DF032BE7A237@automagic.org> <CAHw9_iKWhRjK6yzSSWVsCBqjdVfTnzVkUh8PMYC5nwQUb_=yvw@mail.gmail.com> <20180622191334.GA15349@jurassic> <CAHw9_iLN0w=k0hZLsOCJXnA58afACuzxgXdYPPEn_HShm6Q4aw@mail.gmail.com>
In-Reply-To: <CAHw9_iLN0w=k0hZLsOCJXnA58afACuzxgXdYPPEn_HShm6Q4aw@mail.gmail.com>
From: Shumon Huque <shuque@gmail.com>
Date: Fri, 22 Jun 2018 15:51:25 -0400
Message-ID: <CAHPuVdXZtVRbjO+xL=8Ur=ksag2Op7F-nBLqGHf=c1xdR2x4Lg@mail.gmail.com>
To: Warren Kumari <warren@kumari.net>
Cc: muks@mukund.org, Tony Finch <dot@dotat.at>, "dnsop@ietf.org WG" <dnsop@ietf.org>, jabley@automagic.org, Ray Bellis <ray@bellis.me.uk>
Content-Type: multipart/alternative; boundary="00000000000016001f056f405cc3"
Archived-At: <https://mailarchive.ietf.org/arch/msg/dnsop/UAGpQNJGr1SUl00wRS7DjxnBTMw>
Subject: Re: [DNSOP] abandoning ANAME and standardizing CNAME at apex
X-BeenThere: dnsop@ietf.org
X-Mailman-Version: 2.1.26
Precedence: list
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dnsop>, <mailto:dnsop-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dnsop/>
List-Post: <mailto:dnsop@ietf.org>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dnsop>, <mailto:dnsop-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 22 Jun 2018 19:51:44 -0000

On Fri, Jun 22, 2018 at 3:27 PM Warren Kumari <warren@kumari.net> wrote:

> On Fri, Jun 22, 2018 at 3:13 PM Mukund Sivaraman <muks@mukund.org> wrote:
>
>>
>> With additional-from-cache (default on), BIND will return address of
>> target of SRV if it is already in cache. The second RTT will get
>> amortized. It won't take a lot to make it fetch and return the target
>> too, if it isn't found in cache.
>>
>>
> ​Ah, fair nuff.
> I had tested this against a local bind instance, but didn't think to
> manually trigger the target lookup to get it into the cache.
>
> After doing so, it does indeed stuff it in the additional section.
>
> I'm not sure if my host (OS X) will make use of it, but that's a local
> issue...
>
> W
>
>
I just tested Google Public DNS, Cloudflare DNS, and OpenDNS.

None of them return address records for the SRV targets in the additional
section of their responses, even after priming their caches by querying the
targets first.

As for BIND, my resolver instances have been using "minimal-responses yes"
for a while, and they behave the same.

So, there might still be latency issue that could be improved ..

Shumon.