Re: [DNSOP] DNAMEs in the root zone? [was: Re: draft-grothoff-iesg-special-use-p2p-names-00.txt]

Mark Andrews <marka@isc.org> Mon, 09 December 2013 22:51 UTC

Return-Path: <marka@isc.org>
X-Original-To: dnsop@ietfa.amsl.com
Delivered-To: dnsop@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id CFEDE1A1F54 for <dnsop@ietfa.amsl.com>; Mon, 9 Dec 2013 14:51:34 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.002
X-Spam-Level:
X-Spam-Status: No, score=-2.002 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id ebxRjsZ2w-Hz for <dnsop@ietfa.amsl.com>; Mon, 9 Dec 2013 14:51:33 -0800 (PST)
Received: from mx.pao1.isc.org (mx.pao1.isc.org [IPv6:2001:4f8:0:2::2b]) by ietfa.amsl.com (Postfix) with ESMTP id 670991A1F1A for <dnsop@ietf.org>; Mon, 9 Dec 2013 14:51:33 -0800 (PST)
Received: from mx.pao1.isc.org (localhost [127.0.0.1]) by mx.pao1.isc.org (Postfix) with ESMTP id 4B8A5C942B; Mon, 9 Dec 2013 22:51:15 +0000 (UTC) (envelope-from marka@isc.org)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=isc.org; s=dkim2012; t=1386629488; bh=HdmOgGy866ksVIWcrw1mM0r81yA9SyouTWUeFHFZ1lQ=; h=To:Cc:From:References:Subject:In-reply-to:Date; b=qaofuPgD7yaLhIonyPvRl5crgUjoMZYPZrjyfcpVTCVOJ9UDJ4tgUvGEKRvXjctwt Vxr6VJQcSzNwqGVRwPJvQhqieFVceiIrlS5kuZxyjHXWOBTgW/wypcgjSXqNXFudAr CxF2hjTwEAnDZkTSZKxP5Y59/mg41Jalc9Nn1Nbk=
Received: from zmx1.isc.org (zmx1.isc.org [149.20.0.20]) by mx.pao1.isc.org (Postfix) with ESMTP; Mon, 9 Dec 2013 22:51:15 +0000 (UTC) (envelope-from marka@isc.org)
Received: from zmx1.isc.org (localhost [127.0.0.1]) by zmx1.isc.org (Postfix) with ESMTP id A87D4160459; Mon, 9 Dec 2013 22:59:28 +0000 (UTC)
Received: from rock.dv.isc.org (c211-30-183-50.carlnfd1.nsw.optusnet.com.au [211.30.183.50]) by zmx1.isc.org (Postfix) with ESMTPSA id 7695A160446; Mon, 9 Dec 2013 22:59:28 +0000 (UTC)
Received: from rock.dv.isc.org (localhost [IPv6:::1]) by rock.dv.isc.org (Postfix) with ESMTP id 08F06B6B510; Tue, 10 Dec 2013 09:51:13 +1100 (EST)
To: cet1@cam.ac.uk
From: Mark Andrews <marka@isc.org>
References: <BF87877A-8989-4AA4-9ED1-52C82E1BC538@nominum.com> <alpine.LFD.2.10.1312011206480.12923@bofh.nohats.ca> <20131202151651.GD16808@mx1.yitter.info> <A12FD3E0-58F6-4490-877F-A9C59405F717@vpnc.org> <6DBBC8339C394DBDAE4FE1F764E02A8D@hopcount.ca> <20131203170825.GA17211@nic.fr> <21D03162-81D1-494A-89A9-41BE89D28A0E@nominum.com> <BB7627E9-8D50-48E5-B809-64AE4D574271@virtualized.org> <20131203221006.GB5689@sources.org> <D3E446D0-F9ED-4671-A1C2-29A15D3DE010@virtualized.org> <20131204094449.GA5492@nic.fr> <9650BF6D-727B-4EF3-B357-7E4E2FDDE0AF@virtualized.org> <2614C613-1399-429D-856B-5E2C18DCA7A6@kumari.net> <1DA98CD6C61144088EA480D71E51AF3D@hopcount.ca> <Prayer.1.3.5.1312051215460.21609@hermes-2.csi.cam.ac.uk> <0AE0E07B-2509-440D-81CF-4A75A7F95F45@hopcount.ca> <Prayer.1.3.5.1312091441040.15674@hermes-2.csi.cam.ac.uk>
In-reply-to: Your message of "09 Dec 2013 14:41:04 -0000." <Prayer.1.3.5.1312091441040.15674@hermes-2.csi.cam.ac.uk>
Date: Tue, 10 Dec 2013 09:51:13 +1100
Message-Id: <20131209225113.08F06B6B510@rock.dv.isc.org>
X-DCC--Metrics: post.isc.org; whitelist
Cc: IETF DNSOP WG <dnsop@ietf.org>, Joe Abley <jabley@hopcount.ca>
Subject: Re: [DNSOP] DNAMEs in the root zone? [was: Re: draft-grothoff-iesg-special-use-p2p-names-00.txt]
X-BeenThere: dnsop@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dnsop>, <mailto:dnsop-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/dnsop/>
List-Post: <mailto:dnsop@ietf.org>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dnsop>, <mailto:dnsop-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 09 Dec 2013 22:51:35 -0000

In message <Prayer.1.3.5.1312091441040.15674@hermes-2.csi.cam.ac.uk>, Chris Tho
mpson writes:
> On Dec 7 2013, Joe Abley wrote:
> 
> >On 2013-12-05, at 07:15, Chris Thompson <cet1@cam.ac.uk> wrote:
> [...]
> >> How would such DNAMEs interact with use of BIND's "root-delegation-only"
> >> (or equivalents, if any, in other software)? Do we have any idea how
> >> widespread use of that option is?
> >
> >I don't recall there ever being a time when the default behaviour of BIND9
> >was to insist on delegation-only behaviour from the *root* zone. As I
> >remember those fun and exciting, lawyer-infested times the delegation-only
> >behaviour was applied to all TLD zones, except those that were specified
> >as needing to be otherwise.
> 
> Well the BIND9 ARM says
> 
> | root-delegation-only
> |
> |  Turn on enforcement of delegation-only in TLDs (top level domains)
> |  and root zones with an optional exclude list.
> 
> so I presume it *is* meant to apply to the root zone. In the absence
> of an offending RR in the real root zone, I suppose I would have to
> set up a configuration with a fake root to confirm that. 
> 
> root-delegation-only has never been a distribution BIND default, and
> the words about it in the ARM should be enough to put anyone reading
> them off the idea, Could it be in packaged configurations, though?
> Or just in private configurations dating from the 10-years-ago
> "*.com" wildcard era and not modified since?

And if they have it and then some lookups will fail until they fix
their configuration.  You can say similar things about running old
servers which have bugs in DNAME handling.  One can play "what if"
games all day.

> -- 
> Chris Thompson               University of Cambridge Computing Service,
> Email: cet1@ucs.cam.ac.uk    Roger Needham Building, 7 JJ Thomson Avenue,
> Phone: +44 1223 334715       Cambridge CB3 0RB, United Kingdom.
> _______________________________________________
> DNSOP mailing list
> DNSOP@ietf.org
> https://www.ietf.org/mailman/listinfo/dnsop
-- 
Mark Andrews, ISC
1 Seymour St., Dundas Valley, NSW 2117, Australia
PHONE: +61 2 9871 4742                 INTERNET: marka@isc.org