Re: [DNSOP] the root is not special, everybody please stop obsessing over it

Tony Finch <> Fri, 15 February 2019 09:47 UTC

Return-Path: <>
Received: from localhost (localhost []) by (Postfix) with ESMTP id 35F89130F9A for <>; Fri, 15 Feb 2019 01:47:53 -0800 (PST)
X-Virus-Scanned: amavisd-new at
X-Spam-Flag: NO
X-Spam-Score: -4.199
X-Spam-Status: No, score=-4.199 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Received: from ([]) by localhost ( []) (amavisd-new, port 10024) with ESMTP id 1CjcYUtQ2OGl for <>; Fri, 15 Feb 2019 01:47:51 -0800 (PST)
Received: from ( []) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by (Postfix) with ESMTPS id 0AE37130F5F for <>; Fri, 15 Feb 2019 01:47:51 -0800 (PST)
X-Cam-AntiVirus: no malware found
Received: from ([]:43768) by ( []:25) with esmtps (TLSv1.2:ECDHE-RSA-AES256-GCM-SHA384:256) id 1gua61-000HZw-1q (Exim 4.91) (return-path <>); Fri, 15 Feb 2019 09:47:49 +0000
Date: Fri, 15 Feb 2019 09:47:49 +0000
From: Tony Finch <>
To: Paul Vixie <>
In-Reply-To: <>
Message-ID: <>
References: <>
User-Agent: Alpine 2.20 (DEB 67 2015-01-07)
MIME-Version: 1.0
Content-Type: text/plain; charset="US-ASCII"
Archived-At: <>
Subject: Re: [DNSOP] the root is not special, everybody please stop obsessing over it
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: IETF DNSOP WG mailing list <>
List-Unsubscribe: <>, <>
List-Archive: <>
List-Post: <>
List-Help: <>
List-Subscribe: <>, <>
X-List-Received-Date: Fri, 15 Feb 2019 09:47:53 -0000

Paul Vixie <> wrote:

> unbound has pioneered a bit of this by automatically refetching data that's
> near its expiration point.

BIND also does this, it's on by default.

I'm not a fan of RFC 7706 because I think it's redundant wrt prefetch
(HAMMER), NXDOMAIN synthesis, and (to a much smaller extent) serve-stale.

> the fact that i have to hotwire my RDNS cache with local zone glue in order to
> reach my own servers when my comcast circuit is down or i can't currently
> reach the .SU authorities to learn where VIX.SU is, should not only concern,
> but also embarrass, all of us.

We have local stealth secondary copies of our zones on our recursive
servers which helps to some extent, except when downstream validators want
to get the chain of trust. But serve-stale should help.

I wonder if it's worth having different prefetch logic for infrastructure
records (NS, DS, glue, etc) to more eagerly keep them warm than leaf

f.anthony.n.finch  <>
Northwest Southeast Iceland: Northeasterly 5 or 6, becoming variable 3 or 4.
Rough. Wintry showers. Good, occasionally poor.