[DNSOP] Re: draft-ietf-dnsop-3901bis-10 telechat Dnsdir review

Joe Abley <jabley@strandkip.nl> Fri, 09 January 2026 10:49 UTC

Return-Path: <jabley@strandkip.nl>
X-Original-To: dnsop@mail2.ietf.org
Delivered-To: dnsop@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 0C7C3A54AB81; Fri, 9 Jan 2026 02:49:26 -0800 (PST)
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.799
X-Spam-Level:
X-Spam-Status: No, score=-2.799 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, RCVD_IN_VALIDITY_SAFE_BLOCKED=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=strandkip.nl
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 0pu168rsxhmv; Fri, 9 Jan 2026 02:49:25 -0800 (PST)
Received: from outbound.soverin.net (outbound.soverin.net [185.233.34.146]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 68D99A54AB7C; Fri, 9 Jan 2026 02:49:25 -0800 (PST)
Received: from smtp.soverin.net (unknown [10.10.4.100]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits)) (No client certificate requested) by outbound.soverin.net (Postfix) with ESMTPS id 4dndnB0RJkz9p; Fri, 9 Jan 2026 10:49:18 +0000 (UTC)
Received: from smtp.soverin.net (smtp.soverin.net [10.10.4.100]) by soverin.net (Postfix) with ESMTPSA id 4dndn93KGrzF2; Fri, 9 Jan 2026 10:49:17 +0000 (UTC)
Authentication-Results: smtp.soverin.net; dkim=pass (2048-bit key; unprotected) header.d=strandkip.nl header.i=@strandkip.nl header.a=rsa-sha256 header.s=soverin1 header.b=T8R44QXf; dkim-atps=neutral
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=strandkip.nl; s=soverin1; t=1767955757; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=/h9sXIusgGx8c13QpnmNgAbRe4L+slKBEmkBurQR7m8=; b=T8R44QXf/P219oRJZJ/9laLoaOJ0JJTiHbMfhgWVz+wNNcF5vaQH4HEubAxpQ3dBsohyQr mm960qmys6CpVVC4Zf2SuVQV4J/QZ049RfEL1Kto11LJ+GOXAMlaCRlep3/+hKt8/+gDuX +SF2ic8cuRxE5iUXkwo4H0LYoSh86Kses1YVK/I5g8yZc/tudbXXNMWeIGxqCgS3gPcr4r IFyfYjpmIBGfcjCStE6lvK+0NXnxPPlVij02M3EOWp9WDzHVX3ZpMq8lWfPhFySWVkoz6+ 3STgyQ12yCeYQJZxAEd9Lh9oW02Viz1UNzb/FxHgABHnreBIa9cpzYo1veMVsA==
X-CMAE-Score: 0
X-CM-Analysis: v=2.4 cv=d/oPyQjE c=1 sm=1 tr=0 ts=6960dd2d a=seZ3V8lqfxkj7gJxUOygWg==:617 a=xqWC_Br6kY4A:10 a=kj9zAlcOel0A:10 a=48vgC7mUAAAA:8 a=bNMS9LIhpu1pA1iQsR0A:9 a=CjuIK1q_8ugA:10 a=ADiJHLWpjGBBXEl7-v_j:22
X-CM-Envelope: MS4xfMQxTESsRE7wqJfMWWAmlGmXD2QSiSpa5PhmQ6FsXa0Ao7tyo0zualBaNwgpbsfzvaWmjA+PjwEwWihxyeQ4aynYxXm5BHjZTXmBJmCdCIhj1uHhIIbj 9oFzpkuSOMzHrlaPWRQWpQCXZ9fth730yVTY1vaQ8hESyogx+z49QBI1FqKFwAcSiaMBovZS+cqksq1x9onk3ukX3kYwjCucLBqvOqRV38hwMhegtQy0F5LL zRRSTyhgktTGIeUP6XmZ9frjZFkxIwSYk9+7POwu2rqUHlrtjT1AUds5qjnM+xNn
X-Soverin-Id: 019ba25f-f7c8-7ebe-b7fc-f2ab588fc0d7
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
From: Joe Abley <jabley@strandkip.nl>
Mime-Version: 1.0 (1.0)
Date: Fri, 09 Jan 2026 11:49:06 +0100
Message-Id: <D1756F96-A565-4A2B-92FC-B09180ACF69B@strandkip.nl>
References: <13152225d5175dc923a7081792cc38b7907537a5.camel@fiebig.nl>
In-Reply-To: <13152225d5175dc923a7081792cc38b7907537a5.camel@fiebig.nl>
To: tobias@fiebig.nl
X-Spampanel-Class: ham
Message-ID-Hash: ZVUYHNWQ56IQ33DUD2BDRXQLI5LNCVRW
X-Message-ID-Hash: ZVUYHNWQ56IQ33DUD2BDRXQLI5LNCVRW
X-MailFrom: jabley@strandkip.nl
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-dnsop.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: dnsop@ietf.org, ops-ads@ietf.org
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [DNSOP] Re: draft-ietf-dnsop-3901bis-10 telechat Dnsdir review
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/dnsop/b4e93qArGjPKF_Wl1s8DrFIaDJo>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dnsop>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Owner: <mailto:dnsop-owner@ietf.org>
List-Post: <mailto:dnsop@ietf.org>
List-Subscribe: <mailto:dnsop-join@ietf.org>
List-Unsubscribe: <mailto:dnsop-leave@ietf.org>

Hi Tobias,

A small reaction to one thing you said, on a tagent from Geoff's wider review:

On 9 Jan 2026, at 10:36, Tobias Fiebig <tobias=40fiebig.nl@dmarc.ietf.org> wrote:

>> 4. Section 4.2: "when responding to recursive queries sent by stub
>> DNS". How can a recursive resolver know that a query has been sent by
>> a stub resolver?
> 
> RFC1035 defines an 'RD' bit in DNS queries. If it is present in a
> query, a recursive resolver can safely assume that the query has not
> been sent by a recursive resolver acting as a recursive resolver for
> this specific query.

This is not true ("safely assume"). There is a complex graph of actors between stub resolvers and authority servers in the real world, many of which originate queries with RD=1. 

For example, ISP resolvers which forward queries to public resolvers with RD=1 are commonplace.  Home gateways that receive queries from devices within the home, and forward to other upstream resolvers with RD=1 following a cache miss are commonplace. These are not niche configurations.

I have not read your proposed changes to the text to address the comment from Geoff that prompted your response above, but if it is based on the "safe assumption" above you may want to revisit it.


Joe