Re: [DNSOP] fyi [Pdns-users] Please test: ALIAS/ANAME apex record in PowerDNS
Dick Franks <rwfranks@acm.org> Mon, 22 September 2014 13:27 UTC
Return-Path: <rwfranks@gmail.com>
X-Original-To: dnsop@ietfa.amsl.com
Delivered-To: dnsop@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id D09571A1AD3 for <dnsop@ietfa.amsl.com>; Mon, 22 Sep 2014 06:27:59 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.277
X-Spam-Level:
X-Spam-Status: No, score=-1.277 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, FM_FORGED_GMAIL=0.622, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, SPF_PASS=-0.001] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id rexyRA8jOHDs for <dnsop@ietfa.amsl.com>; Mon, 22 Sep 2014 06:27:59 -0700 (PDT)
Received: from mail-we0-x22d.google.com (mail-we0-x22d.google.com [IPv6:2a00:1450:400c:c03::22d]) (using TLSv1 with cipher ECDHE-RSA-RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id B718C1A1AD4 for <dnsop@ietf.org>; Mon, 22 Sep 2014 06:27:55 -0700 (PDT)
Received: by mail-we0-f173.google.com with SMTP id x48so1469749wes.18 for <dnsop@ietf.org>; Mon, 22 Sep 2014 06:27:54 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=mime-version:sender:in-reply-to:references:from:date:message-id :subject:to:cc:content-type; bh=yGZD3EUc96Cfq+XTjqRoA9VjTh/lYYWINI37NJePbpI=; b=BBffFpZXbUW5IDt1G86j9E650LIzrvCvxIrI1y/6OuUXIaJVkAe6mPnc1cM5F+NWjf poYY6mQ9XWxpC74kU+lZgIX5IPxPXWUMSWR6OfZ6po6vcPOIAIWke3OP8dSdy2K4zXda YAd382YAYPPoBVLEgy1IMfGPMQm89R9uTiYNNIJTrumaqOMCZDPZMX6Ipzv85R1Iarm3 fh+YWoUyGD0k7GrFrpDMRHxDhAb6wMfHlrX15NcGgsclTl/ZYQHh6/BX69XxeCXhSjFu emo/kli6JZLP9m0U25Bnku8RsGxcCnt514kjYfs9S03ySoLK2WRawMOzsZXvsW5xM1HX iFxQ==
X-Received: by 10.180.95.35 with SMTP id dh3mr15224566wib.24.1411392474381; Mon, 22 Sep 2014 06:27:54 -0700 (PDT)
MIME-Version: 1.0
Sender: rwfranks@gmail.com
Received: by 10.180.106.137 with HTTP; Mon, 22 Sep 2014 06:27:14 -0700 (PDT)
In-Reply-To: <alpine.LSU.2.00.1409221223281.3000@hermes-1.csi.cam.ac.uk>
References: <20140921115222.GB16178@xs.powerdns.com> <541F1AE8.6010709@redbarn.org> <alpine.LSU.2.00.1409221047520.3000@hermes-1.csi.cam.ac.uk> <CAKW6Ri7HYB0BdHGJG9aTXs3=JP4wG1B5uZpk7Y0S60XGAXayQw@mail.gmail.com> <alpine.LSU.2.00.1409221223281.3000@hermes-1.csi.cam.ac.uk>
From: Dick Franks <rwfranks@acm.org>
Date: Mon, 22 Sep 2014 14:27:14 +0100
X-Google-Sender-Auth: 53nAqjHRI4TU2fahpxBE4CtsC-8
Message-ID: <CAKW6Ri7OYZKEJ88eGRhfuRUqBqZ3XDVOfKci0E8Y=bS3GnawFw@mail.gmail.com>
To: Tony Finch <dot@dotat.at>
Content-Type: multipart/alternative; boundary="f46d04447e1d1305770503a76b61"
Archived-At: http://mailarchive.ietf.org/arch/msg/dnsop/myJqdhcrIvLI50x6ihF9J4nkxBU
Cc: dnsop@ietf.org
Subject: Re: [DNSOP] fyi [Pdns-users] Please test: ALIAS/ANAME apex record in PowerDNS
X-BeenThere: dnsop@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dnsop>, <mailto:dnsop-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/dnsop/>
List-Post: <mailto:dnsop@ietf.org>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dnsop>, <mailto:dnsop-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 22 Sep 2014 13:28:00 -0000
On 22 September 2014 12:27, Tony Finch <dot@dotat.at> wrote: > Dick Franks <rwfranks@acm.org> wrote: > > On 22 September 2014 11:03, Tony Finch <dot@dotat.at> wrote: > > > > > > (1) Master-only. The master observes an ANAME record at the apex of a > zone > > > it loads and uses it to periodically refresh the relevant records in > the > > > zone (as if you had a cron job running dig | magic | nsupdate). > > > > > > Disadvantage: potentially lots of XFR traffic if the TTLs are low. > > > > Why would TTL be relevant here? > > > > Is the master not acting as a "partial slave" for the target RRs? > > In which case, the timing should depend on the SOA refresh period. > > Yes, you could do it that way. But a lot of people want changes to take > effect quickly. > > So whenever TTL times out, master does validated lookup of each ANAME target, resigns, updates zone, notifies own slaves, services XFRs. Someone beyond your direct control sets a short TTL (0 or 1) in ANAME target RRs and your master is in deep, deep [trouble] !! Thinking about it, (target side) SOA refresh is not much better. > And I forgot to cover the effects that client-subnet might have ... > > I do not know either Rs Dick
- Re: [DNSOP] fyi [Pdns-users] Please test: ALIAS/A… Paul Vixie
- [DNSOP] fyi [Pdns-users] Please test: ALIAS/ANAME… bert hubert
- Re: [DNSOP] fyi [Pdns-users] Please test: ALIAS/A… Paul Hoffman
- Re: [DNSOP] fyi [Pdns-users] Please test: ALIAS/A… bert hubert
- Re: [DNSOP] fyi [Pdns-users] Please test: ALIAS/A… Dick Franks
- Re: [DNSOP] fyi [Pdns-users] Please test: ALIAS/A… Suzanne Woolf
- Re: [DNSOP] fyi [Pdns-users] Please test: ALIAS/A… Doug Barton
- Re: [DNSOP] fyi [Pdns-users] Please test: ALIAS/A… Doug Barton
- Re: [DNSOP] fyi [Pdns-users] Please test: ALIAS/A… David Conrad
- Re: [DNSOP] fyi [Pdns-users] Please test: ALIAS/A… Paul Vixie
- Re: [DNSOP] fyi [Pdns-users] Please test: ALIAS/A… David Conrad
- Re: [DNSOP] fyi [Pdns-users] Please test: ALIAS/A… Colm MacCárthaigh
- Re: [DNSOP] fyi [Pdns-users] Please test: ALIAS/A… Paul Vixie
- Re: [DNSOP] fyi [Pdns-users] Please test: ALIAS/A… Suzanne Woolf
- Re: [DNSOP] fyi [Pdns-users] Please test: ALIAS/A… Tony Finch
- Re: [DNSOP] fyi [Pdns-users] Please test: ALIAS/A… Tony Finch
- Re: [DNSOP] fyi [Pdns-users] Please test: ALIAS/A… Tony Finch
- Re: [DNSOP] fyi [Pdns-users] Please test: ALIAS/A… John Levine
- Re: [DNSOP] fyi [Pdns-users] Please test: ALIAS/A… Dick Franks
- Re: [DNSOP] fyi [Pdns-users] Please test: ALIAS/A… Tony Finch
- Re: [DNSOP] fyi [Pdns-users] Please test: ALIAS/A… Andrew Sullivan
- Re: [DNSOP] fyi [Pdns-users] Please test: ALIAS/A… Dick Franks
- Re: [DNSOP] DNSSEC and ALIAS/ANAME apex record in… Paul Hoffman
- Re: [DNSOP] fyi [Pdns-users] Please test: ALIAS/A… Tony Finch
- Re: [DNSOP] fyi [Pdns-users] Please test: ALIAS/A… Colm MacCárthaigh
- Re: [DNSOP] fyi [Pdns-users] Please test: ALIAS/A… Olafur Gudmundsson
- Re: [DNSOP] fyi [Pdns-users] Please test: ALIAS/A… bert hubert
- Re: [DNSOP] fyi [Pdns-users] Please test: ALIAS/A… bert hubert
- Re: [DNSOP] fyi [Pdns-users] Please test: ALIAS/A… Paul Wouters