Re: [DNSOP] Draft Reverse DNS in IPv6 for Internet Service Providers

Ralf Weber <dns@fl1ger.de> Sun, 09 November 2014 22:54 UTC

Return-Path: <dns@fl1ger.de>
X-Original-To: dnsop@ietfa.amsl.com
Delivered-To: dnsop@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 3E5851A8760 for <dnsop@ietfa.amsl.com>; Sun, 9 Nov 2014 14:54:26 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.901
X-Spam-Level:
X-Spam-Status: No, score=-1.901 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 9EqrLKm14VIb for <dnsop@ietfa.amsl.com>; Sun, 9 Nov 2014 14:54:24 -0800 (PST)
Received: from nox.guxx.net (nox.guxx.net [78.46.109.173]) by ietfa.amsl.com (Postfix) with ESMTP id 0E96D1A8756 for <dnsop@ietf.org>; Sun, 9 Nov 2014 14:54:24 -0800 (PST)
Received: by nox.guxx.net (Postfix, from userid 65534) id 21F4ADB8056; Sun, 9 Nov 2014 23:54:23 +0100 (CET)
Received: from [192.168.1.2] (165.sub-70-197-92.myvzw.com [70.197.92.165]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by nox.guxx.net (Postfix) with ESMTPSA id 4077BDB8022; Sun, 9 Nov 2014 23:54:19 +0100 (CET)
Content-Type: text/plain; charset="us-ascii"
Mime-Version: 1.0 (Mac OS X Mail 8.1 \(1993\))
From: Ralf Weber <dns@fl1ger.de>
In-Reply-To: <20141109.190544.78788387.sthaug@nethelp.no>
Date: Sun, 09 Nov 2014 16:54:13 -0600
Content-Transfer-Encoding: quoted-printable
Message-Id: <6C6D2BC0-4099-4F9C-ADE4-F9DD021DA40A@fl1ger.de>
References: <20141106002831.9845623414E0@rock.dv.isc.org> <20141106.082617.74732200.sthaug@nethelp.no> <20141109173601.GA18664@nic.fr> <20141109.190544.78788387.sthaug@nethelp.no>
To: Lee@asgard.org
X-Mailer: Apple Mail (2.1993)
Archived-At: http://mailarchive.ietf.org/arch/msg/dnsop/o1U35mG9pHs99OBbz5iKNJ78iqk
Cc: dnsop WG <dnsop@ietf.org>
Subject: Re: [DNSOP] Draft Reverse DNS in IPv6 for Internet Service Providers
X-BeenThere: dnsop@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dnsop>, <mailto:dnsop-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/dnsop/>
List-Post: <mailto:dnsop@ietf.org>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dnsop>, <mailto:dnsop-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sun, 09 Nov 2014 22:54:26 -0000

Moin!

Read this draft on the way to the IETF and while saw there was a lot of discussion around it I didn't read all of it, so forgive me if stuff has been said before.

First I think it is good to have a draft that captures what you can do and what the challenges for IPv6 reverse are. However as the discussion on what is the best way to do will never come to an end as people have strong opinions on that we should leave that or the recommendations section out of the draft and just publish it as informational. You could if you want to leave that section in just say that there is no clear way to recommend anything as there are different scenarios that apply to different operators and that everybody has to pick their own poison ;-).

One thing I would like to see added is delegating reverse and corresponding forward to CPE (homenet router), but serving it out of the service providers name servers as described in https://tools.ietf.org/html/draft-mglt-homenet-front-end-naming-delegation-04 (full disclosure I am co-author of this). While I like the idea of delegating the naming responsibility to the end user/home I personally don't think it is a good thing for the Internet to generate millions of DNS servers on CPE devices as we already have enough problems with that (http://openresolverproject.org granted different kind of dns server/proxy but I assume hackers will find way to abuse these also).

So long
-Ralf
---
Ralf Weber
e: dns@fl1ger.de