Re: [DNSOP] Special-use TLDs in resolvers

Christian Huitema <huitema@huitema.net> Fri, 16 August 2019 17:26 UTC

Return-Path: <huitema@huitema.net>
X-Original-To: dnsop@ietfa.amsl.com
Delivered-To: dnsop@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 0F1981200D8 for <dnsop@ietfa.amsl.com>; Fri, 16 Aug 2019 10:26:37 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.598
X-Spam-Level:
X-Spam-Status: No, score=-2.598 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_LOW=-0.7, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 6EUpNgyLzZbJ for <dnsop@ietfa.amsl.com>; Fri, 16 Aug 2019 10:26:34 -0700 (PDT)
Received: from mx36-out10.antispamcloud.com (mx36-out10.antispamcloud.com [209.126.121.30]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id B2A90120041 for <dnsop@ietf.org>; Fri, 16 Aug 2019 10:26:34 -0700 (PDT)
Received: from xse411.mail2web.com ([66.113.197.157] helo=xse.mail2web.com) by mx62.antispamcloud.com with esmtp (Exim 4.89) (envelope-from <huitema@huitema.net>) id 1hyfzj-0000O8-Re for dnsop@ietf.org; Fri, 16 Aug 2019 19:26:33 +0200
Received: from xsmtp22.mail2web.com (unknown [10.100.68.61]) by xse.mail2web.com (Postfix) with ESMTPS id 4699GY3QfMz55wy for <dnsop@ietf.org>; Fri, 16 Aug 2019 10:26:29 -0700 (PDT)
Received: from [10.5.2.35] (helo=xmail10.myhosting.com) by xsmtp22.mail2web.com with esmtps (TLS1.0:DHE_RSA_AES_256_CBC_SHA1:256) (Exim 4.92) (envelope-from <huitema@huitema.net>) id 1hyfzh-0007Uz-BC for dnsop@ietf.org; Fri, 16 Aug 2019 10:26:29 -0700
Received: (qmail 9349 invoked from network); 16 Aug 2019 17:19:48 -0000
Received: from unknown (HELO [192.168.1.108]) (Authenticated-user:_huitema@huitema.net@[172.58.43.143]) (envelope-sender <huitema@huitema.net>) by xmail10.myhosting.com (qmail-ldap-1.03) with ESMTPA for <ajs@anvilwalrusden.com>; 16 Aug 2019 17:19:47 -0000
To: Steve Crocker <steve@shinkuro.com>, Joe Abley <jabley@hopcount.ca>
Cc: dnsop <dnsop@ietf.org>, Andrew Sullivan <ajs@anvilwalrusden.com>
References: <a6f528a1-01d0-3bd5-1a7f-96ff4e9bcd85@nic.cz> <20190816144655.jxd37dwn2t4ywuko@mx4.yitter.info> <CABf5zv+cCrQxCeOC1qsijSpujZYqhOB0EuzrTbG+yEX6we0jpQ@mail.gmail.com> <DE6E82A3-A610-4339-970E-876C5CE4727E@hopcount.ca> <CABf5zvLFJhtoyiHbmBheuEBN==LKg1b97uv7efVVMCHMA4AuUQ@mail.gmail.com>
From: Christian Huitema <huitema@huitema.net>
Openpgp: preference=signencrypt
Autocrypt: addr=huitema@huitema.net; prefer-encrypt=mutual; keydata= mQENBFIRX8gBCAC26usy/Ya38IqaLBSu33vKD6hP5Yw390XsWLaAZTeQR64OJEkoOdXpvcOS HWfMIlD5s5+oHfLe8jjmErFAXYJ8yytPj1fD2OdSKAe1TccUBiOXT8wdVxSr5d0alExVv/LO I/vA2aU1TwOkVHKSapD7j8/HZBrqIWRrXUSj2f5n9tY2nJzG9KRzSG0giaJWBfUFiGb4lvsy IaCaIU0YpfkDDk6PtK5YYzuCeF0B+O7N9LhDu/foUUc4MNq4K3EKDPb2FL1Hrv0XHpkXeMRZ olpH8SUFUJbmi+zYRuUgcXgMZRmZFL1tu6z9h6gY4/KPyF9aYot6zG28Qk/BFQRtj7V1ABEB AAG0J0NocmlzdGlhbiBIdWl0ZW1hIDxodWl0ZW1hQGh1aXRlbWEubmV0PokBOQQTAQIAIwUC UhFfyAIbLwcLCQgHAwIBBhUIAgkKCwQWAgMBAh4BAheAAAoJEJNDCbJVyA1yhbYH/1ud6x6m VqGIp0JcZUfSQO8w+TjugqxCyGNn+w/6Qb5O/xENxNQ4HaMQ5uSRK9n8WKKDDRSzwZ4syKKf wbkfj05vgFxrjCynVbm1zs2X2aGXh+PxPL/WHUaxzEP7KjYbLtCUZDRzOOrm+0LMktngT/k3 6+EZoLEM52hwwpIAzJoscyEz7QfqMOZtFm6xQnlvDQeIrHx0KUvwo/vgDLK3SuruG1CSHcR0 D24kEEUa044AIUKBS3b0b8AR7f6mP2NcnLpdsibtpabi9BzqAidcY/EjTaoea46HXALk/eJd 6OLkLE6UQe1PPzQC4jB7rErX2BxnSkHDw50xMgLRcl5/b1a5AQ0EUhFfyAEIAKp7Cp8lqKTV CC9QiAf6QTIjW+lie5J44Ad++0k8gRgANZVWubQuCQ71gxDWLtxYfFkEXjG4TXV/MUtnOliG 5rc2E+ih6Dg61Y5PQakm9OwPIsOx+2R+iSW325ngln2UQrVPgloO83QiUoi7mBJPbcHlxkhZ bd3+EjFxSLIQogt29sTcg2oSh4oljUpz5niTt69IOfZx21kf29NfDE+Iw56gfrxI2ywZbu5o G+d0ZSp0lsovygpk4jK04fDTq0vxjEU5HjPcsXC4CSZdq5E2DrF4nOh1UHkHzeaXdYR2Bn1Y wTePfaHBFlvQzI+Li/Q6AD/uxbTM0vIcsUxrv3MNHCUAEQEAAYkCPgQYAQIACQUCUhFfyAIb LgEpCRCTQwmyVcgNcsBdIAQZAQIABgUCUhFfyAAKCRC22tOSFDh1UOlBB/94RsCJepNvmi/c YiNmMnm0mKb6vjv43OsHkqrrCqJSfo95KHyl5Up4JEp8tiJMyYT2mp4IsirZHxz/5lqkw9Az tcGAF3GlFsj++xTyD07DXlNeddwTKlqPRi/b8sppjtWur6Pm+wnAHp0mQ7GidhxHccFCl65w uT7S/ocb1MjrTgnAMiz+x87d48n1UJ7yIdI41Wpg2XFZiA9xPBiDuuoPwFj14/nK0elV5Dvq 4/HVgfurb4+fd74PV/CC/dmd7hg0ZRlgnB5rFUcFO7ywb7/TvICIIaLWcI42OJDSZjZ/MAzz BeXm263lHh+kFxkh2LxEHnQGHCHGpTYyi4Z3dv03HtkH/1SI8joQMQq00Bv+RdEbJXfEExrT u4gtdZAihwvy97OPA2nCdTAHm/phkzryMeOaOztI4PS8u2Ce5lUB6P/HcGtK/038KdX5MYST Fn8KUDt4o29bkv0CUXwDzS3oTzPNtGdryBkRMc9b+yn9+AdwFEH4auhiTQXPMnl0+G3nhKr7 jvzVFJCRif3OAhEm4vmBNDE3uuaXFQnbK56GJrnqVN+KX5Z3M7X3fA8UcVCGOEHXRP/aubiw Ngawj0V9x+43kUapFp+nF69R53UI65YtJ95ec4PTO/Edvap8h1UbdEOc4+TiYwY1TBuIKltY 1cnrjgAWUh/Ucvr++/KbD9tD6C8=
Message-ID: <bdd279f7-facc-6785-e725-88059e680a57@huitema.net>
Date: Fri, 16 Aug 2019 10:19:49 -0700
User-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; rv:60.0) Gecko/20100101 Thunderbird/60.8.0
MIME-Version: 1.0
In-Reply-To: <CABf5zvLFJhtoyiHbmBheuEBN==LKg1b97uv7efVVMCHMA4AuUQ@mail.gmail.com>
Content-Type: multipart/alternative; boundary="------------3A80B9F31C7EF9921BE8FE99"
Content-Language: en-US
X-Originating-IP: 66.113.197.157
X-Spampanel-Domain: xsmtpout.mail2web.com
X-Spampanel-Username: 66.113.197.0/24
Authentication-Results: antispamcloud.com; auth=pass smtp.auth=66.113.197.0/24@xsmtpout.mail2web.com
X-Spampanel-Outgoing-Class: ham
X-Spampanel-Outgoing-Evidence: Combined (0.05)
X-Recommended-Action: accept
X-Filter-ID: Mvzo4OR0dZXEDF/gcnlw0Wp43USNh4+oPQIPr3x336CpSDasLI4SayDByyq9LIhVwqOMMmkCtas9 N1wXGtycLkTNWdUk1Ol2OGx3IfrIJKywOmJyM1qr8uRnWBrbSAGDwMrZRqsFCjz8E32pWQuD5pj9 EvBvwu01uVCaGVBWGqsBFpMf6giVA0b+Pm5aP+U/2rBNMmEsKEibQwSU1xBeOHButNDpi1WUXRkr He1vFsYm1aGKgRFqmjZjxZofiz4rBXfTi7gDmaugbDBQV1VSRryme9ldZJ7uNXfg/GfS8fXOC4kn OJkMS8NGDKsP9r3Khy7LI0kfFnXdPP6btp4oBeJDeKRq5oPj2hFJhLx+qI3HlR3ootg7OlA3N5WN re/oppAGOX5cHTu1yz4pRT/9FGrxEaaKeSxe0Wrx6M4G5/WoLsdfEoJI0BNUQ4KpaNyNCwGqOUcw rXf55E8Tb8bmXq4yH8StrboPphDtmrtUkwlUgiZZ2raUFFZA8s/fhxGt7T02ZXdoQxMs//iOE4Fl hiCv9TR+UxzLZWL8hwGBjhoI3W+YcuHfP5PkZb5A+wE5qGdpH54Oa3V8I76VOEvlwB+XPdEXquZ7 t0MUOMrNUB3ffy/lWBtKgE7/B4q5Qh1ghmT60YdsojnGXfPCiCYXxQa6h0656Xm8/UklmxZA8Urv 5pWb82qAoDl3ILGSF0vmDvI0DEihOd7XzCAIcFZdY11677oPXF7r5zsW33ZNliqQWXiK63IBlEyx 50xFFL1+cKaDTe3QRRhTm1Fh3Md1t8o3vnim0hzLBdJch5K54yQZ2dCdcTip1fHHY3m3LffWHHAS JNUmoOHSoqgqxfHmWRWcrRhLeB34s3hUb32GO+1hNYXNgcs+0SVc2d1xnZBR08QV3No+S2msRDep v5w/kkG0v17AmegcpQ0tml/sN9lmMy/o83jVXTcfb9k0nLWblJy7uxV6dw8jzlsaNZe6hynMJcjx DydxsJEju76A7X1QIVydqXpZ6MHhiKws9Iiut28r9wo4SqUIg8Yh9hAM0n3LLzx/F2gT3wl8JQJv Bho=
X-Report-Abuse-To: spam@quarantine9.antispamcloud.com
Archived-At: <https://mailarchive.ietf.org/arch/msg/dnsop/rD7z19IgAfCZVpRJHmhg_f74ans>
Subject: Re: [DNSOP] Special-use TLDs in resolvers
X-BeenThere: dnsop@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dnsop>, <mailto:dnsop-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dnsop/>
List-Post: <mailto:dnsop@ietf.org>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dnsop>, <mailto:dnsop-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 16 Aug 2019 17:26:37 -0000

To put things in perspective, the special use TLD defined according to
RFC 6761 account for about 4% of the traffic seen at the L root,
according to https://ithi.research.icann.org/graph-m3.html. Of those,
".local" account for a bit more than 3%, ".localhost" a bit less than
0.5%, and ".invalid" a bit more than 0.25%. The other reserved names see
very little traffic.

There are other sources of noise at the root, including traffic to
".home" (more than 2.5%), ".lan" (a bit less than 1%), ".internal",
".ip", ".dhcp" and ".localdomain", each accounting for about 0.5% of
traffic.

This pales in comparison to the computer generated unique names, which
account for 50% of the traffic seen at the root -- about equally spread
between generated lengths of 7 to 15 characters.

-- Christian Huitema

On 8/16/2019 8:59 AM, Steve Crocker wrote:
> Ack.  Tnx.
>
> On Fri, Aug 16, 2019 at 11:56 AM Joe Abley <jabley@hopcount.ca
> <mailto:jabley@hopcount.ca>> wrote:
>
>     On 16 Aug 2019, at 10:59, Steve Crocker <steve@shinkuro.com
>     <mailto:steve@shinkuro.com>> wrote:
>
>     > At the risk of revealing that I haven't been following this
>     thread carefully, I don't understand how a resolver is supposed to
>     know all of the special names.  Resolvers that are configured to
>     know that invalid, local, onion, and test are special will not
>     know about the next name that's put on the special list.
>
>     The pragmatic answer right now is that vendors and package
>     maintainers do a good job with their default configurations. DNS
>     software tends to get upgraded frequently enough in applications
>     with significant user bases that this goes some of the distance.
>
>     I can see your point though that there might be some merit in
>     having a way to retrieve a current list, or at least telling
>     whether the list you have is up-to-date. I don't know that I think
>     it's a particularly pressing problem though (I think DNSSEC trust
>     anchor distribution for the root zone is higher up the priority
>     list, for example).
>
>
>     Joe
>
>
> _______________________________________________
> DNSOP mailing list
> DNSOP@ietf.org
> https://www.ietf.org/mailman/listinfo/dnsop