Re: [DNSOP] Review of draft-livingood-dns-redirect-00

Alan Barrett <apb@cequrux.com> Tue, 14 July 2009 06:50 UTC

Return-Path: <apb@cequrux.com>
X-Original-To: dnsop@core3.amsl.com
Delivered-To: dnsop@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id 06C773A672F for <dnsop@core3.amsl.com>; Mon, 13 Jul 2009 23:50:09 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.529
X-Spam-Level:
X-Spam-Status: No, score=-1.529 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, DATE_IN_PAST_06_12=1.069, NORMAL_HTTP_TO_IP=0.001]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id f-nfJCCgRc6O for <dnsop@core3.amsl.com>; Mon, 13 Jul 2009 23:50:08 -0700 (PDT)
Received: from citadel.cequrux.com (citadel.cequrux.com [192.96.22.18]) by core3.amsl.com (Postfix) with ESMTP id 320EA3A6AD7 for <dnsop@ietf.org>; Mon, 13 Jul 2009 23:49:34 -0700 (PDT)
Received: (from nobody@localhost) by citadel.cequrux.com (8.12.11/8.12.11) id n6E6lonx036137 for <dnsop@ietf.org>; Tue, 14 Jul 2009 08:47:50 +0200 (SAST) (envelope-from apb@cequrux.com)
Received: by citadel.cequrux.com via recvmail id 36126; Tue, 14 Jul 2009 08:47:49 +0200 (SAST)
Date: Mon, 13 Jul 2009 22:13:45 +0200
From: Alan Barrett <apb@cequrux.com>
To: dnsop@ietf.org
Message-ID: <20090713201345.GA675@apb-laptoy.apb.alt.za>
References: <C67B83C4.E855%Jason_Livingood@cable.comcast.com>
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Disposition: inline
In-Reply-To: <C67B83C4.E855%Jason_Livingood@cable.comcast.com>
Subject: Re: [DNSOP] Review of draft-livingood-dns-redirect-00
X-BeenThere: dnsop@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
Reply-To: dnsop@ietf.org
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/dnsop>, <mailto:dnsop-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/dnsop>
List-Post: <mailto:dnsop@ietf.org>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dnsop>, <mailto:dnsop-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 14 Jul 2009 06:50:09 -0000

On Thu, 09 Jul 2009, Livingood, Jason wrote:
> I submitted this draft, which you can find at
> http://tools.ietf.org/html/draft-livingood-dns-redirect-00, before
> the =??00 cutoff on Monday, and it will be discussed in the DNSOP WG
> meeting at IETF 75 (it is listed on the agenda).

I think that this sort of lying recursive resolver is a bad idea.
Instead, I suggest a new "SUGGESTION" RR type that could be returned
in the additional section of an error message.  For example, if
you ask for www.example.invalid, you could get back an NXDOMAIN
error, with "SUGGESTION URL=http://10.2.3.4/www.example.invalid"
in the additional section, and if you ask for censored.example.
you could get back a SERVFAIL response with "SUGGESTION
URL=http://10.2.3.4/why-we-censor.html" in the additional section.

Clients who want to follow such suggestions can then do so, without
harming clients who don't want to be lied to.

--apb (Alan Barrett)