Re: [DNSOP] draft-fujiwara-dnsop-nsec-aggressiveuse-01.txt

Shumon Huque <shuque@gmail.com> Mon, 26 October 2015 15:54 UTC

Return-Path: <shuque@gmail.com>
X-Original-To: dnsop@ietfa.amsl.com
Delivered-To: dnsop@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id AD67A1B2FF8 for <dnsop@ietfa.amsl.com>; Mon, 26 Oct 2015 08:54:19 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.999
X-Spam-Level:
X-Spam-Status: No, score=-1.999 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id WhQtoZSeAkdG for <dnsop@ietfa.amsl.com>; Mon, 26 Oct 2015 08:54:17 -0700 (PDT)
Received: from mail-qg0-x22d.google.com (mail-qg0-x22d.google.com [IPv6:2607:f8b0:400d:c04::22d]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id A3EFA1B2FB3 for <dnsop@ietf.org>; Mon, 26 Oct 2015 08:54:17 -0700 (PDT)
Received: by qgad10 with SMTP id d10so122727180qga.3 for <dnsop@ietf.org>; Mon, 26 Oct 2015 08:54:16 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=mime-version:in-reply-to:references:date:message-id:subject:from:to :cc:content-type; bh=g+O3Mz84bMyTwzacYZUFe8XoA4Ew3ZxGHvzttlY4dT4=; b=DOWZRurZLg6mmUH34OWbkWQNvWtTdgifz5wKWCtQ6nEezRSMIZLKfB1NcS+6hKDDHD 9DHGfrToRHEHwyDpiYvSRjJNGJVcgCFGzC+sm0gkksM+OOK6Hv8bfUMrf1vTRcHpdsk+ YxfWbI4qf97cBrUFrezOF1AVsjmFDYOSP+PhWlqZIe48OintNjgx/Z8fYoWMO4oUHWsJ xL0dIfjJKwjQECEIFpUBuLyKPMQQaBxxf2Jb/d/hYRnJXq/c4H16+bHszOCPbkwbaAjU fPPynMK9uYW5DCgkoIWXh/3wDpaUIrkjReCBUf7c2+XlFf66IQbTvpQwY0FqEi37dRkl uN+A==
MIME-Version: 1.0
X-Received: by 10.140.104.243 with SMTP id a106mr41744341qgf.19.1445874856796; Mon, 26 Oct 2015 08:54:16 -0700 (PDT)
Received: by 10.140.80.170 with HTTP; Mon, 26 Oct 2015 08:54:16 -0700 (PDT)
In-Reply-To: <20151025104914.GA23386@sources.org>
References: <20150310.191541.52184726.fujiwara@jprs.co.jp> <20150707.182043.193693838.fujiwara@jprs.co.jp> <CAJE_bqcRQH0WGTaLqtMSuiOty4KHe9nN6T-wmqf3x_ohuA6TcA@mail.gmail.com> <20151024191654.GA3560@sources.org> <5753B8EC-60EC-44F3-872E-94766558EE50@redbarn.org> <20151025104914.GA23386@sources.org>
Date: Mon, 26 Oct 2015 11:54:16 -0400
Message-ID: <CAHPuVdU4E_Rz-E-HgbRzJtY31J9WW3-yFZzS25FHY2azY3BL5A@mail.gmail.com>
From: Shumon Huque <shuque@gmail.com>
To: Stephane Bortzmeyer <bortzmeyer@nic.fr>
Content-Type: multipart/alternative; boundary="001a1134f6d63aaa51052303f947"
Archived-At: <http://mailarchive.ietf.org/arch/msg/dnsop/vXrq7Vh7gx5RTnc-DBxvB1B6kIo>
Cc: dnsop <dnsop@ietf.org>, P Vixie <paul@redbarn.org>
Subject: Re: [DNSOP] draft-fujiwara-dnsop-nsec-aggressiveuse-01.txt
X-BeenThere: dnsop@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dnsop>, <mailto:dnsop-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dnsop/>
List-Post: <mailto:dnsop@ietf.org>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dnsop>, <mailto:dnsop-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 26 Oct 2015 15:54:19 -0000

On Sun, Oct 25, 2015 at 6:49 AM, Stephane Bortzmeyer <bortzmeyer@nic.fr>
wrote:

> On Sat, Oct 24, 2015 at 10:54:15PM +0000,
>  P Vixie <paul@redbarn.org> wrote
>  a message of 73 lines which said:
>
> > To me this is a feature, possibly the most important feature.
>
> Specially now that Akamai's authoritative name servers properly handle
> ENTs:
>
> % dig @n6dscx.akamaiedge.net A dscx.akamaiedge.net
>
> ; <<>> DiG 9.9.5-9+deb8u3-Debian <<>> @n6dscx.akamaiedge.net A
> dscx.akamaiedge.net
> ; (1 server found)
> ;; global options: +cmd
> ;; Got answer:
> ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 11794
> ;; flags: qr aa rd ad; QUERY: 1, ANSWER: 0, AUTHORITY: 1, ADDITIONAL: 0
> ;; WARNING: recursion requested but not available
>


Hmm, what is the original full query name you were trying to resolve here
Stephane?

Perhaps it's fixed in the akamaiedge.net zone, but it isn't fixed in
another Akamai zone I just tested (edgesuite.net):

>> Resolving 'www.upenn.edu'
>> Query: edu. A IN at zone .
>>        [Got Referral to zone: edu.]
>> Query: upenn.edu. A IN at zone edu.
>>        [Got Referral to zone: upenn.edu.]
>> Query: www.upenn.edu. A IN at zone upenn.edu.
www.upenn.edu. 300 IN CNAME www.upenn.edu-dscg.edgesuite.net.
>> Query: net. A IN at zone .
>>        [Got Referral to zone: net.]
>> Query: edgesuite.net. A IN at zone net.
>>        [Got Referral to zone: edgesuite.net.]
>> Query: edu-dscg.edgesuite.net. A IN at zone edgesuite.net.
ERROR: NXDOMAIN: edu-dscg.edgesuite.net. not found
www.upenn.edu. 300 IN CNAME www.upenn.edu-dscg.edgesuite.net.

Shumon Huque