[DNSOP] Re: [v6ops] Re: Re: Re: Moving DNS64 (RFC6147) to Internet Standard

Michael Richardson <mcr+ietf@sandelman.ca> Mon, 13 April 2026 14:55 UTC

Return-Path: <mcr+ietf@sandelman.ca>
X-Original-To: dnsop@mail2.ietf.org
Delivered-To: dnsop@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id D410ADB4F0F3; Mon, 13 Apr 2026 07:55:00 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1776092100; bh=bJn4e1Boi1zAhP3AtRhWyjBQEMdHGly7HLuMq9duavY=; h=From:To:Subject:In-Reply-To:References:Date; b=Z9Xb8wwEdd1KD3Mxa3Lsm6nNUs82CdBHQGq+cpZ1a06+V+FRSCPQUBr4f+kpG+/cN 7gdNJv3lHP8IE1XXAB1qk6BmziIHDrMd2wKUb0Xe/8lQP8iFyb9sHVL8U7fCQ6+n7c jnLsOdzamYoj+PR4/whfK8zhx1XZmLSZb3OLpIe4=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.8
X-Spam-Level:
X-Spam-Status: No, score=-2.8 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_LOW=-0.7, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=sandelman.ca
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id KqXBgwYaOvVN; Mon, 13 Apr 2026 07:55:00 -0700 (PDT)
Received: from tuna.sandelman.ca (tuna.sandelman.ca [IPv6:2607:f0b0:f:3:216:3eff:fe7c:d1f3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id A2EC9DB4EFD8; Mon, 13 Apr 2026 07:53:47 -0700 (PDT)
Received: from localhost (localhost [127.0.0.1]) by tuna.sandelman.ca (Postfix) with ESMTP id 0EA0A39F39; Mon, 13 Apr 2026 10:53:47 -0400 (EDT)
Received: from tuna.sandelman.ca ([127.0.0.1]) by localhost (localhost [127.0.0.1]) (amavis, port 10024) with LMTP id KQ__jx9Dj366; Mon, 13 Apr 2026 10:53:45 -0400 (EDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=sandelman.ca; s=mail; t=1776092025; bh=Vk97rav7zgNwSO7tt5/QIyfBxZr/EI+PRtaMQTJnhfQ=; h=From:To:Subject:In-Reply-To:References:Date:From; b=V/Dm5ALjrYr9n2TmMTdQgdaXtJwd2YZUfB2jdqLgofDR0PlDMnMFMZ2pkZ1ZuUqSh ELMmqk2CRFRehvD3QcwAIUrfZjzBMqMwQb5CBWDE0DmJRtf3ZrckJYQsCSPYZknyhW d+gL65rN+kE/cNxzg8rrpiIBCJ7g5G9WyVC3JDIaEy3mN+WmtQ2QF4T25/EP+OkT1d 09w7NQKLMOYCfOZ/vsA+VmYsiPsoNlZSeOGID96mzbDR3fOSXIziuvXk13Fo5972mI 3F+YWQSHw7f+p4I0KG8uwKXazNz7Y7pD3JECnErxXLYeOaUbTUtgJi2+m1cihpTlwX QoBziZ5ouM1ug==
Received: from sandelman.ca (obiwan.sandelman.ca [IPv6:2607:f0b0:f:2::247]) by tuna.sandelman.ca (Postfix) with ESMTP id 1ADE739EAF; Mon, 13 Apr 2026 10:53:45 -0400 (EDT)
Received: from obiwan.sandelman.ca (obiwan.sandelman.ca [127.0.0.1]) by sandelman.ca (Postfix) with ESMTP id 169121CD; Mon, 13 Apr 2026 10:53:45 -0400 (EDT)
From: Michael Richardson <mcr+ietf@sandelman.ca>
To: Philip Homburg <pch-dnsop-7@u-1.phicoh.com>, dnsop@ietf.org, "jordi.palet@consulintel.es" <jordi.palet=40consulintel.es@dmarc.ietf.org>, IPv6 Operations <v6ops@ietf.org>
In-Reply-To: <m1wCHbM-0000ORC@stereo.hq.phicoh.net>
References: <m1wAunU-0000NEC@stereo.hq.phicoh.net> <2338256.t9SDvczpPo@localhost> <038ae9d1-34fc-4085-aa6d-76ef79287857@gmail.com> <PARP264MB6760A67BB8F2060962E8A64088592@PARP264MB6760.FRAP264.PROD.OUTLOOK.COM> <B93DB6C8-2974-4915-93DE-DFCB6B858AFA@consulintel.es> <m1wB6jW-0000VYC@stereo.hq.phicoh.net> <9A70D5B5-F58A-471E-9CC6-7A0874B53B80@consulintel.es> <m1wCHbM-0000ORC@stereo.hq.phicoh.net>
X-Mailer: MH-E 8.6+git; nmh 1.8+dev; Emacs 30.1
X-Face: $\n1pF)h^`}$H>Hk{L"x@)JS7<%Az}5RyS@k9X%29-lHB$Ti.V>2bi.~ehC0;<'$9xN5Ub# z!G,p`nR&p7Fz@^UXIn156S8.~^@MJ*mMsD7=QFeq%AL4m<nPbLgmtKK-5dC@#:k
MIME-Version: 1.0
Content-Type: multipart/signed; boundary="=-=-="; micalg="pgp-sha512"; protocol="application/pgp-signature"
Date: Mon, 13 Apr 2026 10:53:45 -0400
Message-ID: <13416.1776092025@obiwan.sandelman.ca>
Message-ID-Hash: EIQZI7SJRHFOMGLGZSLNNQCFYS77FWKL
X-Message-ID-Hash: EIQZI7SJRHFOMGLGZSLNNQCFYS77FWKL
X-MailFrom: mcr+ietf@sandelman.ca
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-dnsop.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [DNSOP] Re: [v6ops] Re: Re: Re: Moving DNS64 (RFC6147) to Internet Standard
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/dnsop/lpObzqWCtbDO-UKlqoS-bCt5_7o>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dnsop>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Owner: <mailto:dnsop-owner@ietf.org>
List-Post: <mailto:dnsop@ietf.org>
List-Subscribe: <mailto:dnsop-join@ietf.org>
List-Unsubscribe: <mailto:dnsop-leave@ietf.org>

Philip Homburg <pch-dnsop-7@u-1.phicoh.com> wrote:
    > You never installed a DNSSEC validating proxy on a laptop without CLAT?

Yes, I've done it.  Any bog-standard Ubuntu laptop with systemd-resolve usually has
DNSSEC enabled, and has no CLAT.  (Of course, systemd-resolver screws up so
badly for other reasons, one usually has to disable it)
I agree, it's a fail.

    >> I think the point is to understand that DNSSEC with DNS64 is broken
    >> only in a very very very small % of situation, which can also be
    >> resolved.

    > The problem with DNS64 is that it seems to work (to some extent at least)
    > without CLAT. But as soon as you install a DNSSEC validating proxy,
    > or some other DNSSEC validation, access to IPv4 is lost.

From what I understand, Smartphones, Windows and OSX all have CLATs, but do
not come with DNSSEC enabled by default.  I think that those systems are all
moving (perhaps slowly) to PREF64 and local synthesis.  That's good, right?

    > That means that devices that rely on DNS64 make it is a lot harder to
    > deploy those technologies.

Only if they are mobile/nomadic.
If they stay in one place, one does whatever the correct thing is.
Remember that people deploying IPv6-{mostly,only} **today** know what the correct
thing is.   If DNS64 goes away, then many servers will have to go back to
dual-stack.  That's who loses.

--
Michael Richardson <mcr+IETF@sandelman.ca>   . o O ( IPv6 IøT consulting )
           Sandelman Software Works Inc, Ottawa and Worldwide

**       My working hours and your working hours may be different.         **
** Please do not feel obligated to reply outside your normal working hours **