Re: [DNSOP] fyi [Pdns-users] Please test: ALIAS/ANAME apex record in PowerDNS

Dick Franks <rwfranks@acm.org> Mon, 22 September 2014 13:27 UTC

Return-Path: <rwfranks@gmail.com>
X-Original-To: dnsop@ietfa.amsl.com
Delivered-To: dnsop@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id D09571A1AD3 for <dnsop@ietfa.amsl.com>; Mon, 22 Sep 2014 06:27:59 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.277
X-Spam-Level:
X-Spam-Status: No, score=-1.277 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, FM_FORGED_GMAIL=0.622, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, SPF_PASS=-0.001] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id rexyRA8jOHDs for <dnsop@ietfa.amsl.com>; Mon, 22 Sep 2014 06:27:59 -0700 (PDT)
Received: from mail-we0-x22d.google.com (mail-we0-x22d.google.com [IPv6:2a00:1450:400c:c03::22d]) (using TLSv1 with cipher ECDHE-RSA-RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id B718C1A1AD4 for <dnsop@ietf.org>; Mon, 22 Sep 2014 06:27:55 -0700 (PDT)
Received: by mail-we0-f173.google.com with SMTP id x48so1469749wes.18 for <dnsop@ietf.org>; Mon, 22 Sep 2014 06:27:54 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=mime-version:sender:in-reply-to:references:from:date:message-id :subject:to:cc:content-type; bh=yGZD3EUc96Cfq+XTjqRoA9VjTh/lYYWINI37NJePbpI=; b=BBffFpZXbUW5IDt1G86j9E650LIzrvCvxIrI1y/6OuUXIaJVkAe6mPnc1cM5F+NWjf poYY6mQ9XWxpC74kU+lZgIX5IPxPXWUMSWR6OfZ6po6vcPOIAIWke3OP8dSdy2K4zXda YAd382YAYPPoBVLEgy1IMfGPMQm89R9uTiYNNIJTrumaqOMCZDPZMX6Ipzv85R1Iarm3 fh+YWoUyGD0k7GrFrpDMRHxDhAb6wMfHlrX15NcGgsclTl/ZYQHh6/BX69XxeCXhSjFu emo/kli6JZLP9m0U25Bnku8RsGxcCnt514kjYfs9S03ySoLK2WRawMOzsZXvsW5xM1HX iFxQ==
X-Received: by 10.180.95.35 with SMTP id dh3mr15224566wib.24.1411392474381; Mon, 22 Sep 2014 06:27:54 -0700 (PDT)
MIME-Version: 1.0
Sender: rwfranks@gmail.com
Received: by 10.180.106.137 with HTTP; Mon, 22 Sep 2014 06:27:14 -0700 (PDT)
In-Reply-To: <alpine.LSU.2.00.1409221223281.3000@hermes-1.csi.cam.ac.uk>
References: <20140921115222.GB16178@xs.powerdns.com> <541F1AE8.6010709@redbarn.org> <alpine.LSU.2.00.1409221047520.3000@hermes-1.csi.cam.ac.uk> <CAKW6Ri7HYB0BdHGJG9aTXs3=JP4wG1B5uZpk7Y0S60XGAXayQw@mail.gmail.com> <alpine.LSU.2.00.1409221223281.3000@hermes-1.csi.cam.ac.uk>
From: Dick Franks <rwfranks@acm.org>
Date: Mon, 22 Sep 2014 14:27:14 +0100
X-Google-Sender-Auth: 53nAqjHRI4TU2fahpxBE4CtsC-8
Message-ID: <CAKW6Ri7OYZKEJ88eGRhfuRUqBqZ3XDVOfKci0E8Y=bS3GnawFw@mail.gmail.com>
To: Tony Finch <dot@dotat.at>
Content-Type: multipart/alternative; boundary="f46d04447e1d1305770503a76b61"
Archived-At: http://mailarchive.ietf.org/arch/msg/dnsop/myJqdhcrIvLI50x6ihF9J4nkxBU
Cc: dnsop@ietf.org
Subject: Re: [DNSOP] fyi [Pdns-users] Please test: ALIAS/ANAME apex record in PowerDNS
X-BeenThere: dnsop@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dnsop>, <mailto:dnsop-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/dnsop/>
List-Post: <mailto:dnsop@ietf.org>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dnsop>, <mailto:dnsop-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 22 Sep 2014 13:28:00 -0000

On 22 September 2014 12:27, Tony Finch <dot@dotat.at> wrote:

> Dick Franks <rwfranks@acm.org> wrote:
> > On 22 September 2014 11:03, Tony Finch <dot@dotat.at> wrote:
> > >
> > > (1) Master-only. The master observes an ANAME record at the apex of a
> zone
> > > it loads and uses it to periodically refresh the relevant records in
> the
> > > zone (as if you had a cron job running dig | magic | nsupdate).
> > >
> > > Disadvantage: potentially lots of XFR traffic if the TTLs are low.
> >
> > Why would TTL be relevant here?
> >
> > Is the master not acting as a "partial slave" for the target RRs?
> > In which case, the timing should depend on the SOA refresh period.
>
> Yes, you could do it that way. But a lot of people want changes to take
> effect quickly.
>
> So whenever TTL times out, master does validated lookup of each ANAME
target, resigns, updates zone, notifies own slaves, services XFRs.

Someone beyond your direct control sets a short TTL (0 or 1) in ANAME
target RRs and your master is in deep, deep [trouble] !!

Thinking about it, (target side) SOA refresh is not much better.



> And I forgot to cover the effects that client-subnet might have ...
>
>  I do not know either


Rs
Dick