Re: [DNSOP] [Ext] Re: draft-ietf-dnsop-extended-error and combinations of EDEs and RCODEs

Ray Bellis <ray@bellis.me.uk> Fri, 13 September 2019 11:17 UTC

Return-Path: <ray@bellis.me.uk>
X-Original-To: dnsop@ietfa.amsl.com
Delivered-To: dnsop@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 602C4120077 for <dnsop@ietfa.amsl.com>; Fri, 13 Sep 2019 04:17:01 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.9
X-Spam-Level:
X-Spam-Status: No, score=-1.9 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=portfast.net
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Z1cprtx1jylF for <dnsop@ietfa.amsl.com>; Fri, 13 Sep 2019 04:16:58 -0700 (PDT)
Received: from mail.portfast.net (mail.portfast.net [IPv6:2a03:9800:20:1::2]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id A5299120073 for <dnsop@ietf.org>; Fri, 13 Sep 2019 04:16:58 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=portfast.net; s=dkim; h=Content-Transfer-Encoding:Content-Type:In-Reply-To: MIME-Version:Date:Message-ID:From:References:To:Subject:Sender:Reply-To:Cc: Content-ID:Content-Description:Resent-Date:Resent-From:Resent-Sender: Resent-To:Resent-Cc:Resent-Message-ID:List-Id:List-Help:List-Unsubscribe: List-Subscribe:List-Post:List-Owner:List-Archive; bh=ayr23SHNfapmxzLAjNlWoZg/780jO0W3wVoRw8RXgpc=; b=D04AQTUWBuyvhNcllKWZcrPHCM 9dZ61QQsTYrTk5q8JCU011n7gExTL1RFN8xtN4UzjxSZP88UNBGRHc9kS01XCvYCo8RkzVGcH186M ZhwmKnxOexOYENu7xapZM381iH16QRqegoxLxSW2u7zPBOwtj8+GyHgqsnTEPwAOxPRk=;
Received: from [88.212.170.135] (port=56932 helo=Rays-MacBook-Pro.local) by mail.portfast.net ([188.246.200.9]:465) with esmtpsa (fixed_plain:ray@bellis.me.uk) (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) id 1i8jZQ-0002L3-9d (Exim 4.89) for dnsop@ietf.org (return-path <ray@bellis.me.uk>); Fri, 13 Sep 2019 11:16:56 +0000
To: dnsop@ietf.org
References: <EA557043-34D1-43EA-B750-4A17CFC6BE50@icann.org> <ybl36h4aj8x.fsf@w7.hardakers.net> <AFE92D06-8418-4451-A827-D5656C83B796@icann.org> <yblzhjbeova.fsf@w7.hardakers.net> <067589D2-8E7E-47FA-867C-72E266A55D6D@icann.org> <CADyWQ+EB-eotvTdYwNv5Oo4=-mibdgEgpkQ3yh37orAwp-AgWg@mail.gmail.com> <ybly2yubfnp.fsf@w7.hardakers.net> <21136294-FDFD-4A99-9529-E79C45E79535@icann.org> <yblzhja9kz3.fsf@w7.hardakers.net> <3AC375B1-D858-4577-AEBE-4BB7CD40C241@icann.org> <1878161734.14716.1568306548325@appsuite-gw1.open-xchange.com> <0C5DC6B2-E9C5-46A6-B0BA-12830A405DD2@dukhovni.org>
From: Ray Bellis <ray@bellis.me.uk>
Message-ID: <775d97e3-65b0-832a-6118-a3c64d872539@bellis.me.uk>
Date: Fri, 13 Sep 2019 12:16:55 +0100
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.14; rv:60.0) Gecko/20100101 Thunderbird/60.9.0
MIME-Version: 1.0
In-Reply-To: <0C5DC6B2-E9C5-46A6-B0BA-12830A405DD2@dukhovni.org>
Content-Type: text/plain; charset=utf-8; format=flowed
Content-Language: en-GB
Content-Transfer-Encoding: 7bit
Archived-At: <https://mailarchive.ietf.org/arch/msg/dnsop/c8JfrM4Kf0e24fEbBPgKL1xoj1w>
Subject: Re: [DNSOP] [Ext] Re: draft-ietf-dnsop-extended-error and combinations of EDEs and RCODEs
X-BeenThere: dnsop@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dnsop>, <mailto:dnsop-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dnsop/>
List-Post: <mailto:dnsop@ietf.org>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dnsop>, <mailto:dnsop-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 13 Sep 2019 11:17:01 -0000



On 12/09/2019 19:10, Viktor Dukhovni wrote:

> That's the crux of the matter and, in short, *no*, that's not (or should
> not be) the motivation.
> 
> SERVFAIL means,  and will continue to mean, I can't help you, better luck next
> time (or elsewhere).
> 
> The new EDEs are *diagnostic* detail to aid in troubleshoots, but do not
> override RCODEs.  They are not a more fine-grained RCODE one might "act on".
> If we want more fine-grained *actionable* codes, there's plenty of room for
> more values in the 12-bit EDNS RCODE.
> 
> [ I chatted off-list with Wes, the above appears to match his take, with a bit
>    luck also rough WG consensus... ]

The very first two sentences of the draft are (to my reading) at odds 
with that:

"There are many reasons that a DNS query may fail, some of them
  transient, some permanent; some can be resolved by querying another
  server, some are likely best handled by stopping resolution.
  Unfortunately, the error signals that a DNS server can return are
  very limited, and are not very expressive."

Ray