Re: [DNSOP] abandoning ANAME and standardizing CNAME at apex

Joe Abley <> Tue, 19 June 2018 19:05 UTC

Return-Path: <>
Received: from localhost (localhost []) by (Postfix) with ESMTP id BBFA5130DED for <>; Tue, 19 Jun 2018 12:05:40 -0700 (PDT)
X-Virus-Scanned: amavisd-new at
X-Spam-Flag: NO
X-Spam-Score: -1.999
X-Spam-Status: No, score=-1.999 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: (amavisd-new); dkim=pass (1024-bit key)
Received: from ([]) by localhost ( []) (amavisd-new, port 10024) with ESMTP id E7SZD86-4tCT for <>; Tue, 19 Jun 2018 12:05:38 -0700 (PDT)
Received: from ( [IPv6:2607:f8b0:4001:c06::235]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by (Postfix) with ESMTPS id 7A5871294D0 for <>; Tue, 19 Jun 2018 12:05:38 -0700 (PDT)
Received: by with SMTP id u4-v6so1222281iof.2 for <>; Tue, 19 Jun 2018 12:05:38 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;; s=google; h=from:message-id:mime-version:subject:date:in-reply-to:cc:to :references; bh=26wT8G1YEhMZ7PKVdioEdC0XdHegKPj0R/4OkiK+VRA=; b=pQs/UIG92+7NPZGKRyykLrxlUWIXjEk/w3oCpgCLP6okKSs6Uw+9iFv/XzwE4HD8dQ iRHwXu5poSWtPh6ExMm/Lvj/nNQMaGGfeaV1j4kPqqupKtkRwfzz57kshIe443XgngL6 K4cmdVOJGA+fjRry1lVZtt0b7kQOFyCRArjFM=
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;; s=20161025; h=x-gm-message-state:from:message-id:mime-version:subject:date :in-reply-to:cc:to:references; bh=26wT8G1YEhMZ7PKVdioEdC0XdHegKPj0R/4OkiK+VRA=; b=ab6cFQnWsaHzBpijpOSllyRWNQNAVZ1A32qHkA4GNQqeDLMFZC2Wr3pl25EokC47Jm JRzZjhLyuWqLV+FCZlOt/kaGcpBXefPOIg6+tlrZ0OwhbzEHMsGs4hFhr8PNHwMAFgAb sSwsz1uAqF7mN2ooQTML9UHaDGhAZKaLgZ4WaYwJvFaSNk6fXShCmXJ8OiEvOMUGxg+g dwiNg3Afd+y0Mgz8fLg26siYRCYziJ2PxqmQaFs961NveIW+l3anOjLES50t7v+W1GiY MiYkKDF/GbEKQQVK5zS5Mx6OMu2Sm5gvlVSQRbiah/CAhbyjm7NqLYVgyQBIQWe1Fbgl CWHA==
X-Gm-Message-State: APt69E3VG9CEkfKCQ0fOZkUCLgwXIg2ZF//FiPbyIVlzrTmZZjp64wup VSQT6cmJcY16j/1V14IEiVI+VA==
X-Google-Smtp-Source: ADUXVKIumfvrnYLebsDDTylU7PEiYme0vdSF7JcNTfzEpMBKUaxAik+ZfwVsUBI0XyEigH0Wjuwovw==
X-Received: by 2002:a6b:df45:: with SMTP id d5-v6mr13714186iop.230.1529435137664; Tue, 19 Jun 2018 12:05:37 -0700 (PDT)
Received: from ?IPv6:2607:f2c0:101:203:4c29:6cfb:f343:463f? ([2607:f2c0:101:203:4c29:6cfb:f343:463f]) by with ESMTPSA id u196-v6sm383684ita.44.2018. (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Tue, 19 Jun 2018 12:05:36 -0700 (PDT)
From: Joe Abley <>
Message-Id: <>
Content-Type: multipart/signed; boundary="Apple-Mail=_A7A66896-2007-4935-BD49-90A28108003D"; protocol="application/pgp-signature"; micalg=pgp-sha1
Mime-Version: 1.0 (Mac OS X Mail 11.4 \(3445.8.2\))
Date: Tue, 19 Jun 2018 15:05:34 -0400
In-Reply-To: <20180619190213.B76962846E19@ary.qy>
To: John Levine <>
References: <20180619190213.B76962846E19@ary.qy>
X-Mailer: Apple Mail (2.3445.8.2)
Archived-At: <>
Subject: Re: [DNSOP] abandoning ANAME and standardizing CNAME at apex
X-Mailman-Version: 2.1.26
Precedence: list
List-Id: IETF DNSOP WG mailing list <>
List-Unsubscribe: <>, <>
List-Archive: <>
List-Post: <>
List-Help: <>
List-Subscribe: <>, <>
X-List-Received-Date: Tue, 19 Jun 2018 19:05:41 -0000

> On 19 Jun 2018, at 15:02, John Levine <> wrote:
> In article <> you write:
>> This sounds like a lot of work and likely to cause camel indigestion.
> Agreed but it doesn't seem all that much less work than a well
> specified version of ANAME, and it avoids the ANAME ugliness of making
> authoritative servers do recursive lookups.

It's the full mesh of CNAME-related behaviours of all the various actors that gives me the fear, mainly.

At least with a new specification you get to try and start with a clean slate and you generally only need one fall-back behaviour for each kind of actor talking to each other kind of actor; by changing CNAME behaviour (yet again) we'd be making an already hairy situation even more hirsute.