Re: [DNSOP] Draft Reverse DNS in IPv6 for Internet Service Providers

Mark Andrews <marka@isc.org> Mon, 10 November 2014 01:35 UTC

Return-Path: <marka@isc.org>
X-Original-To: dnsop@ietfa.amsl.com
Delivered-To: dnsop@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 63BCA1A8863 for <dnsop@ietfa.amsl.com>; Sun, 9 Nov 2014 17:35:25 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.495
X-Spam-Level:
X-Spam-Status: No, score=-2.495 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RP_MATCHES_RCVD=-0.594, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id XOWCDP6lWOpd for <dnsop@ietfa.amsl.com>; Sun, 9 Nov 2014 17:35:24 -0800 (PST)
Received: from mx.pao1.isc.org (mx.pao1.isc.org [IPv6:2001:4f8:0:2::2b]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 1D6151A8860 for <dnsop@ietf.org>; Sun, 9 Nov 2014 17:35:24 -0800 (PST)
Received: from zmx1.isc.org (zmx1.isc.org [149.20.0.20]) by mx.pao1.isc.org (Postfix) with ESMTP id 5F6AD3493CD; Mon, 10 Nov 2014 01:35:21 +0000 (UTC)
Received: from zmx1.isc.org (localhost [127.0.0.1]) by zmx1.isc.org (Postfix) with ESMTP id 421CF160053; Mon, 10 Nov 2014 01:38:40 +0000 (UTC)
Received: from rock.dv.isc.org (dhcp-b7b7.meeting.ietf.org [31.133.183.183]) by zmx1.isc.org (Postfix) with ESMTPSA id 2C3E1160050; Mon, 10 Nov 2014 01:38:40 +0000 (UTC)
Received: from rock.dv.isc.org (localhost [IPv6:::1]) by rock.dv.isc.org (Postfix) with ESMTP id 36A40235976C; Mon, 10 Nov 2014 12:35:21 +1100 (EST)
To: Ralf Weber <dns@fl1ger.de>
From: Mark Andrews <marka@isc.org>
References: <20141106002831.9845623414E0@rock.dv.isc.org> <20141106.082617.74732200.sthaug@nethelp.no> <20141109173601.GA18664@nic.fr> <20141109.190544.78788387.sthaug@nethelp.no> <6C6D2BC0-4099-4F9C-ADE4-F9DD021DA40A@fl1ger.de>
In-reply-to: Your message of "Sun, 09 Nov 2014 16:54:13 -0600." <6C6D2BC0-4099-4F9C-ADE4-F9DD021DA40A@fl1ger.de>
Date: Mon, 10 Nov 2014 12:35:21 +1100
Message-Id: <20141110013521.36A40235976C@rock.dv.isc.org>
Archived-At: http://mailarchive.ietf.org/arch/msg/dnsop/wrnD7eyiS7iJdu7PGfmRsaZ4dYs
Cc: Lee@asgard.org, dnsop WG <dnsop@ietf.org>
Subject: Re: [DNSOP] Draft Reverse DNS in IPv6 for Internet Service Providers
X-BeenThere: dnsop@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dnsop>, <mailto:dnsop-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/dnsop/>
List-Post: <mailto:dnsop@ietf.org>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dnsop>, <mailto:dnsop-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 10 Nov 2014 01:35:25 -0000

In message <6C6D2BC0-4099-4F9C-ADE4-F9DD021DA40A@fl1ger.de>, Ralf Weber writes:
> Moin!
> 
> Read this draft on the way to the IETF and while saw there was a lot of discu
> ssion around it I didn't read all of it, so forgive me if stuff has been said
>  before.
> 
> First I think it is good to have a draft that captures what you can do and wh
> at the challenges for IPv6 reverse are. However as the discussion on what is 
> the best way to do will never come to an end as people have strong opinions o
> n that we should leave that or the recommendations section out of the draft a
> nd just publish it as informational. You could if you want to leave that sect
> ion in just say that there is no clear way to recommend anything as there are
>  different scenarios that apply to different operators and that everybody has
>  to pick their own poison ;-).
> 
> One thing I would like to see added is delegating reverse and corresponding f
> orward to CPE (homenet router), but serving it out of the service providers n
> ame servers as described in https://tools.ietf.org/html/draft-mglt-homenet-fr
> ont-end-naming-delegation-04 (full disclosure I am co-author of this). While 
> I like the idea of delegating the naming responsibility to the end user/home 
> I personally don't think it is a good thing for the Internet to generate mill
> ions of DNS servers on CPE devices as we already have enough problems with th
> at (http://openresolverproject.org granted different kind of dns server/proxy
>  but I assume hackers will find way to abuse these also).

For the home user CPE you use DNS COOKIES / SIT or push to TCP.  These should
be low volume authoritative server.

> So long
> -Ralf
> ---
> Ralf Weber
> e: dns@fl1ger.de
> 
> 
> 
> _______________________________________________
> DNSOP mailing list
> DNSOP@ietf.org
> https://www.ietf.org/mailman/listinfo/dnsop
-- 
Mark Andrews, ISC
1 Seymour St., Dundas Valley, NSW 2117, Australia
PHONE: +61 2 9871 4742                 INTERNET: marka@isc.org