Re: [DNSOP] Adoption of new EDNS opcode "rrserial"

Peter van Dijk <peter.van.dijk@powerdns.com> Mon, 10 May 2021 21:33 UTC

Return-Path: <peter.van.dijk@powerdns.com>
X-Original-To: dnsop@ietfa.amsl.com
Delivered-To: dnsop@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id E220C3A2BDE for <dnsop@ietfa.amsl.com>; Mon, 10 May 2021 14:33:57 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.197
X-Spam-Level:
X-Spam-Status: No, score=-4.197 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, SPF_HELO_NONE=0.001, SPF_NONE=0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id FB8L-fXIoL3f for <dnsop@ietfa.amsl.com>; Mon, 10 May 2021 14:33:53 -0700 (PDT)
Received: from mx3.open-xchange.com (alcatraz.open-xchange.com [87.191.39.187]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 743613A2BDA for <dnsop@ietf.org>; Mon, 10 May 2021 14:33:53 -0700 (PDT)
Received: from imap.open-xchange.com (imap.open-xchange.com [84.81.54.175]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client did not present a certificate) by mx3.open-xchange.com (Postfix) with ESMTPSA id 4399D6A0D3; Mon, 10 May 2021 23:33:48 +0200 (CEST)
Received: from plato ([84.81.54.175]) by imap.open-xchange.com with ESMTPSA id 2am0D7ymmWDJNQAA3c6Kzw (envelope-from <peter.van.dijk@powerdns.com>); Mon, 10 May 2021 23:33:48 +0200
Message-ID: <2050c0440ffab8d34539a93c47059586285b7e23.camel@powerdns.com>
From: Peter van Dijk <peter.van.dijk@powerdns.com>
To: dnsop@ietf.org
Date: Mon, 10 May 2021 23:33:47 +0200
In-Reply-To: <328e8ade-e95b-2d1f-70c6-04d28ffb74b@dotat.at>
References: <20200127150847.taxhqeipwq6jg2rr@nic.cl> <CAAk_VVivs96dL-qVw8rqSXjkukBFHPyr2htWApbb44SVyQsGag@mail.gmail.com> <20210507164749.GC91746@pepino> <20210510163716.GC5718@pepino> <6d121251eb229ff2e0650da05d447bacc94c2c31.camel@powerdns.com> <328e8ade-e95b-2d1f-70c6-04d28ffb74b@dotat.at>
Organization: PowerDNS.COM B.V.
Content-Type: text/plain; charset="UTF-8"
User-Agent: Evolution 3.30.5-1.1
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Archived-At: <https://mailarchive.ietf.org/arch/msg/dnsop/XVBFVSKazxM5ZuxwazoaVrkH6ac>
Subject: Re: [DNSOP] Adoption of new EDNS opcode "rrserial"
X-BeenThere: dnsop@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dnsop>, <mailto:dnsop-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dnsop/>
List-Post: <mailto:dnsop@ietf.org>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dnsop>, <mailto:dnsop-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 10 May 2021 21:33:58 -0000

On Mon, 2021-05-10 at 22:09 +0100, Tony Finch wrote:
> Peter van Dijk <peter.van.dijk@powerdns.com> wrote:
> > Also in section 3.2, I do not think responding with the option should
> > be limited to NOERROR. Specifically, I'd very much also want it to work
> > for NXDOMAIN,
> 
> Isn't the SOA record usually present in a negative response?

Good point! In that case, I retract most of that and suggest the draft
points out that in those cases, a serial can be extracted anyway. That
said, I'm not sure that's a reason to skip including the option in the
response.

> and I can imagine some cases of it being useful even in SERVFAIL cases
> > (at least in database-driven name servers like PowerDNS, where
> > individual records inside a zone can be broken).
> 
> Perhaps also in cases where the server has a copy of zone serial number
> NNN but it has expired.

+1
 
Kind regards,
-- 
Peter van Dijk
PowerDNS.COM BV - https://www.powerdns.com/