[DNSOP] Re: [v6ops] Corner-case in DNS authority guidance impacting IPv6-only resolvers
mohamed.boucadair@orange.com Tue, 19 May 2026 17:58 UTC
Return-Path: <mohamed.boucadair@orange.com>
X-Original-To: dnsop@mail2.ietf.org
Delivered-To: dnsop@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 4A52EF0EDA4D for <dnsop@mail2.ietf.org>; Tue, 19 May 2026 10:58:44 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1779213524; bh=3UvQDXT/UeEKB+LDkQbhMmqWUcp4q73KhkYml5Xm9K8=; h=From:To:Subject:Date:References:In-Reply-To; b=bWckgDHfShdUigFL9HrdrwhNQ4qtta0cmUOsZwDpYBYe3MOcvKvrmM7+vJKwkOtgY rVNvkKZmjknaUv7y/IXGFDIy1OxYj7lo5epVyij/Ag81+8iQ5Jiun2EgQSHIWtbmVx bNmn+DAkzn+V1X8eEA4HmiL79ME2jgsuKI16adHM=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.795
X-Spam-Level:
X-Spam-Status: No, score=-2.795 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_MSPIKE_H2=0.001, RCVD_IN_VALIDITY_CERTIFIED_BLOCKED=0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, SPF_NONE=0.001, UNPARSEABLE_RELAY=0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=orange.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 5TYXcOjd2EQL for <dnsop@mail2.ietf.org>; Tue, 19 May 2026 10:58:43 -0700 (PDT)
Received: from smtp-out.orange.com (smtp-out.orange.com [80.12.126.238]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 715C8F0EDA48 for <dnsop@ietf.org>; Tue, 19 May 2026 10:58:43 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=orange.com; i=@orange.com; q=dns/txt; s=orange002; t=1779213523; x=1810749523; h=to:subject:date:message-id:references:in-reply-to: mime-version:content-transfer-encoding:from; bh=3UvQDXT/UeEKB+LDkQbhMmqWUcp4q73KhkYml5Xm9K8=; b=ISTK0XgyUAGfwn7wcu7DvmVcCZNFA1RUh0OAVGc7yYH6tHYNpjhK1H2O auxkYMVAXB+SgIyUtMmjo6R2PaY1Jf9HvF+SkjzsMu2DQt2HMtHcoxB5/ /K8dXMWG9zGAEC/2XxZV6PGIPV51oxnfrP9NOmVxPz4Q7EbaV85BpnmdH Duw0mPX2pmzV0fDTraKdfgCAEUUuWwcxe1bOQy2CJ+nTOKwxL8ClreHss lwQgrQbPXntc7n2zkLR7OqhFbVsfq88x7RfqeU+pfMvO/y3+rm6rqMZqB 6gqa9T15Lo0PtVH5dZ4vt7OHccSSJYvJdTpMCut4Jxo/U/M/sr1vnsdIT w==;
X-CSE-ConnectionGUID: nbTOYtX/SzyK040qC4NodQ==
X-CSE-MsgGUID: x+Rni0i2QH2XiM8//L4EtA==
Received: from unknown (HELO opfedv1rlp0b.nor.fr.ftgroup) ([x.x.x.x]) by smtp-out.orange.com with ESMTP/TLS/TLS_AES_256_GCM_SHA384; 19 May 2026 19:58:35 +0200
Received: from unknown (HELO opzinddimail18.si.fr.intraorange) ([x.x.x.x]) by opfedv1rlp0b.nor.fr.ftgroup with ESMTP/TLS/TLS_AES_256_GCM_SHA384; 19 May 2026 19:58:35 +0200
Received: from opzinddimail18.si.fr.intraorange (unknown [127.0.0.1]) by DDEI (Postfix) with ESMTP id 9DB5012AAAE2 for <dnsop@ietf.org>; Tue, 19 May 2026 19:58:30 +0200 (CEST)
Received: from opzinddimail18.si.fr.intraorange (unknown [127.0.0.1]) by DDEI (Postfix) with ESMTP id 872B112AAAD1 for <dnsop@ietf.org>; Tue, 19 May 2026 19:58:25 +0200 (CEST)
Received: from smtp-out365.orange.com (unknown [x.x.x.x]) by opzinddimail18.si.fr.intraorange (Postfix) with ESMTPS for <dnsop@ietf.org>; Tue, 19 May 2026 19:58:25 +0200 (CEST)
Received: from mail-francesouthazlp17010020.outbound.protection.outlook.com (HELO MRZP264CU002.outbound.protection.outlook.com) ([40.93.69.20]) by smtp-out365.orange.com with ESMTP/TLS/TLS_AES_256_GCM_SHA384; 19 May 2026 19:58:25 +0200
Received: from PAUP264MB6756.FRAP264.PROD.OUTLOOK.COM (2603:10a6:102:52c::5) by PR0P264MB2257.FRAP264.PROD.OUTLOOK.COM (2603:10a6:102:16b::9) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.21.48.14; Tue, 19 May 2026 17:58:24 +0000
Received: from PAUP264MB6756.FRAP264.PROD.OUTLOOK.COM ([fe80::8b83:578b:5221:8deb]) by PAUP264MB6756.FRAP264.PROD.OUTLOOK.COM ([fe80::8b83:578b:5221:8deb%4]) with mapi id 15.21.0025.023; Tue, 19 May 2026 17:58:23 +0000
From: mohamed.boucadair@orange.com
X-CSE-ConnectionGUID: 0wXq9HbASvq+ycM+CZMHVQ==
X-CSE-MsgGUID: dbRKKPoeTpOM86++3zDUVw==
X-TM-AS-ERS: 10.218.35.130-127.5.254.253
X-TM-AS-SMTP: 1.0 c210cC1vdXQzNjUub3JhbmdlLmNvbQ== bW9oYW1lZC5ib3VjYWRhaXJAb 3JhbmdlLmNvbQ==
X-DDEI-TLS-USAGE: Used
X-CSE-ConnectionGUID: GRR00z/cRrKddChmgVb4jw==
X-CSE-MsgGUID: m6/ZB1uMR6i1GHE2LyaDhQ==
IronPort-Data: A9a23:PQyWe6pMae99E+0RJd5bi2nQq1xeBmIGZRIvgKrLsJaIsI4StFCzt garIBmEPamMNGP8LY9zbYri9RtQvpeHx4U3TlE//ngwQ3gSpJacVYWSI3mrMnLJJKUvbq7GA +byyDXkBJppJpMJjk71atANlVEli+fQAOC6UbeeUsxIbVcMYD87jh5+kPIOjIdtgNyoayuAo tqaT/f3YDdJ4BYqdDhPg06/gEk35qqq5WpJ5gdWic1j5zcyqVFEVfrzGonhdxMUcqEMdsamS uDKyq2O/2+x138FFtO/n7/nRVYBS7jUMBLmoiI+t3+K20UqSoQai87XBdJEAatlo2zhc+NZk b2hgaeNpTIBZcUgrgi/vy5wSEmSNYUekFPOzOPWXca7lyUqeFO0qxli4d1f0YAwoo5K7W9yG fMwBwo3NkiRwOmM2pG3RsJsg8sdJpXpI9ZK0p1g5Wmx4fcOZKrxe/+UufRlhG9qwMdTAfzZe swVLyJ1awjNaAFOPVFRD48imOCvhT/0dDgwRFC9+fJxsjOVkl03iuCF3Nn9IrRmQe1QmUaRo 2/KuW7+HxoTONWe0xKC6HuqieKJliT+MG4XPOTipq802wPKngT/DjUTCxyJi6Ckr3TgWotwC 2FO3jsngagLoRnDot7VBEbi/CHsUgQnc8ZXGewz8ymDy6fe4gnfAGxsZjJHc9s+nM47WTJs0 UWG9+4FHhRqubyRDHyH/7GfoCi1JDQVJH0GfXZbFVJdu4O75oYukhjIU9BvVravicH4Ei3xx DbMqzUig7IUjogA0KDTEU37byyEiaLzFlYnoQ7tREGp4ih5YYGbbdCq9g2OhRpfF7p1WGVtq 1AqoaCjAA0mCJiMkGmDWuwLF7yy4OuZMDTOhUY2QMF4r2z3ozikYJxa5yx4KAFxKMEYdDT1Y UjV/wRM+JtUO3jsZqhyC25QNyjI5fa/fTgGfqmJBjarXnSXXFPalM2JTRLBt10BaGB2zckC1 W6zKK5A90r29piLPBLtHL1BjtfHNwg7xGjJQov8wQjv2r2EfBaodFvxC3PXNrpRxPrd+G39q o8DX+PUkUk3eLOlOEH/r9VMRW3m2FBnX/gaXeQLLLbbemKL2QgJV5fs/F/WU9A8w/kMy7eSo SDVt40x4AOXuEAr4D6iMhhLAI4Dl74mxZ7nFUTA5WqV5kU=
IronPort-HdrOrdr: A9a23:UNQDGa+U86hTbSeAtJ9uk+F3db1zdoMgy1knxilNoENuH/Bwxv rFoB1E73TJYW4qKQgdcKO7SdG9qBTnhNZICOgqTP6ftWbdyQ6Vxe1Zg7cKhgeQfREWldQtnp uIEZIObOEYZGIS5aqU3OD7KadG/DDtysCVbJLlvhVQpHZRGsJdBmlCazqzIwlbVQNGDZ02GN 6m4NZbpz2vQHITbs6qLHgIVerOqrTw5djbSC9DIyRixBiFjDuu5rK/OQOfxA0iXzRGxqpn2X TZkiTij5/T/82T+1v57Sv+/p5WkNzuxp9oH8qXkPUYLT3ql0KBeJlhYbufpzo4ydvfp2rC0e O87SvIDf4Dq085TVvF4icFHDOQkgrG3kWSiGNwR0GT5PARCghKT/apzrgpCScxo3BQxu2Ulp g7kl5x/qAncS8pkEnGlqX1fgAvmUyurXU4l+kPy3RZTIsFcbdU6ZcS5UVPDf47bVbHAa0cYZ tT5fvnlYNrWELfa2qcsnhkwdSqUHh2FhCaQlIassjQ1zRNhnh2w0YR2cRaxx47heQAYogB4/ 6BPrVjlblIQMNTZaVhBP0ZSc/yDmDWWxrDPG+bPFyiHqAaPHDGrYLx/dwOlZaXUY1NyIF3lI XKUVteu2J3c0XyCdeW1JkO6RzJSHXVZ0Wf9iif3ekIhlTRfsubDcTYciFQryKJmYRgPvHm
X-Talos-CUID: 9a23:bKCGgGz7snOJbv9NMZg5BgU7IPp9Km+ax03KAEO0ImZsR4OfFV2PrfY=
X-Talos-MUID: 9a23:/91Qsgq9/cbTKZwwVdIezzQ8c/VCurmLMh4MyLomlpOgJCVcOw7I2Q==
X-IronPort-AV: E=Sophos;i="6.23,243,1770591600"; d="scan'208";a="128963610"
ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=MkybTqeeLfwLFOhjUIhqXd0A1Uc6oAiLmZuArINoTq9uJ7ZeuLp6rkZLiZxGelTey5YY5IReQ3bjA5Sf5AsNZneddh6KXG6YEye7Zk6HP4CpZMzPTitWZ3jQNeky1nLRE5yMDqI0P3piZCZgSGx5WyV1uFhyfGr/VlTTggKZzNSHY2rOyhdJ14DR+7y9Q6ER8Im6V/wKXjGBSgJjV3qHVWehOpH/XtpXW9C0yyFvx8zYoQs2g7bwWKDNvSXm6kchKjPQsjMZgHw2fsr3lmMEJWXSDqsrMVRb0ICiKpWvVOIzBGCZuH66gkBzb6rfC6w4FOxWIv+jNKDF6++locruaw==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=UE6AHn1/JNVd8N0fv6CBSIbNoY02JRH0XK5sDaL3QpU=; b=DxYmTelzv42HAjsEdqmeV0UKtS5EKv1OL0dHcgrUXchBk3Vo0mGgTuWcIPsSDLUBDxwnEmCfWJqXgbAe9WAhzda8e/4duvZBZ1TY8R9iG8l6mKlUZAtkwmugVAuMzxj1aoJqqSWh8k9mc+ZzTGBjo0md+gnrZnc5najQo5bkCKqjuI83bVoWqEHK4jYdIiS1aSpiu7pYvA8acqooBDz2D+af/p5LKXJZdIR5wVX5OHT8Y+ZvjBtC3ng7ejJWHC99YH8XtagTvVCqZVM2J1/fdXA4HIfZNE70seztNWLRlZi53j5FyWUX9/uLS25NfK5EBc/rfujCvbdg0Jm8zlMAxQ==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=orange.com; dmarc=pass action=none header.from=orange.com; dkim=pass header.d=orange.com; arc=none
To: "tobias@fiebig.nl" <tobias@fiebig.nl>, "dnsop@ietf.org" <dnsop@ietf.org>
Thread-Topic: [DNSOP] Re: [v6ops] Corner-case in DNS authority guidance impacting IPv6-only resolvers
Thread-Index: AQHc57TXOSNil5hQj0O97DxOymtJdLYVoOXw
Date: Tue, 19 May 2026 17:58:23 +0000
Message-ID: <PAUP264MB6756223C298253B8623234F588002@PAUP264MB6756.FRAP264.PROD.OUTLOOK.COM>
References: <CAKC-DJh95eH-FB6vLW0h9wDwOLkSy5WDWKOO7pWLdn-5_kOySg@mail.gmail.com> <PAUP264MB6756ED41E81E82B97E7A9C8888312@PAUP264MB6756.FRAP264.PROD.OUTLOOK.COM> <CAKC-DJhRpGhJB3O2tOkqZUop6AxG6zW2yXb4+F+1NnMSqOgP_w@mail.gmail.com> <6fff78723fe4b902230288a779e3e373f3dac9dc.camel@fiebig.nl>
In-Reply-To: <6fff78723fe4b902230288a779e3e373f3dac9dc.camel@fiebig.nl>
Accept-Language: fr-FR, en-US
Content-Language: fr-FR
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
msip_labels: MSIP_Label_07222825-62ea-40f3-96b5-5375c07996e2_ActionId=22333b50-0591-426e-a940-c5c44fd13b0b;MSIP_Label_07222825-62ea-40f3-96b5-5375c07996e2_ContentBits=0;MSIP_Label_07222825-62ea-40f3-96b5-5375c07996e2_Enabled=true;MSIP_Label_07222825-62ea-40f3-96b5-5375c07996e2_Method=Privileged;MSIP_Label_07222825-62ea-40f3-96b5-5375c07996e2_Name=unrestricted_parent.2;MSIP_Label_07222825-62ea-40f3-96b5-5375c07996e2_SetDate=2026-05-19T17:52:14Z;MSIP_Label_07222825-62ea-40f3-96b5-5375c07996e2_SiteId=90c7a20a-f34b-40bf-bc48-b9253b6f5d20;MSIP_Label_07222825-62ea-40f3-96b5-5375c07996e2_Tag=10, 0, 1, 1;MSIP_Label_f47c794b-e3ab-43f0-9e0f-29fc3e503192_ContentBits=0;MSIP_Label_f47c794b-e3ab-43f0-9e0f-29fc3e503192_Enabled=true;MSIP_Label_f47c794b-e3ab-43f0-9e0f-29fc3e503192_Method=Standard;
authentication-results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=orange.com;
x-ms-publictraffictype: Email
x-ms-traffictypediagnostic: PAUP264MB6756:EE_|PR0P264MB2257:EE_
x-ms-office365-filtering-correlation-id: 8ae82491-68f8-47c0-34bd-08deb5d03886
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0;ARA:13230040|376014|366016|1800799024|4022899009|11063799006|56012099003|22082099003|18002099003|5023799004|38070700021|4143699003;
x-microsoft-antispam-message-info: DfxGS5ekzAfr9zmGjuRX2Y0OXAG5PuJ1m4iZQXQ/DxpmAivFsvT7EfVw9RRmtZHsjV/QY5UvFMZjHooDECXLaptivUvhPGMJY8rCLE4wxmc/3rNr46dOygFaMPdpgECImZFnwGFCYp9UErGNSjTRr2y0NQmqGG3xzJzrzOZXEw/zLy0DDOhTXIRTJlLjabf+nh3p35vXX7SNoe7ymECMET5QJPchhTaReD0v6+O72vZiavv22YY71ozUY4dtPItQfhqE1Wct0xF52lazvaoVRRkzYOT15ELnnzbLRt9eDR1Ou9HmEUmMCKrBw4vvuc6iy3cUzpQUiu3n0E5mik9kN2Bcbu1IIwhOJttNCFsDU2xOg03Xa1PPc8m/tcU0hd0B8fqdeg1P42/zJvgSqF3Nl9Cp7e7xmsfk9Rerjfbhxmo7nuuaf41n/LbeHu87LsbRFkFc4JUjERLzPFblhPvQImR0CQPGdValljiattlqlqG/O3uSNgtS3P/8Gn3gqIs23bWSilb8oEmkrgkrS4hgk/FU1kwmJAxeK/d5UPM+jWl0o9GNVNy0WQqBLe7EXffnBhAnKJv0h7MqetWf3ssMXtmJO9QuXB0fA/kQrBsOmdC5MjEaqP7PxkKqk0AJQ46EHWdS7FuK7xJKgCk/ygisuMXgF4IMXLdIefvmwYfLDnVQ7qCVMl7JZFiRVbeRqWE8Qju8XN7Tx3qDKr/xAFz4gAPHPjG2KfBwcGslvajTiINLD/9SLKtJ36EyOLyeFV/H
x-forefront-antispam-report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:PAUP264MB6756.FRAP264.PROD.OUTLOOK.COM;PTR:;CAT:NONE;SFS:(13230040)(376014)(366016)(1800799024)(4022899009)(11063799006)(56012099003)(22082099003)(18002099003)(5023799004)(38070700021)(4143699003);DIR:OUT;SFP:1101;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: EqK4VkL29WTJCtZXjevrB09QICYAasJN9PAGDK/PngjJ29XcjwYeVrCM3fTLbaiaPhPZgnV9z4KVWBmC55oRoV2b4qjbI3xJoQkCgS3M/F1xvNSZAW2FHgkiYt1iThJwyrjuYGXZNZFD4W61CLAIlxYHf+PKIu51rrWNWGLBx8WhuK9LamP68qwAmuc6FrIqESt12QhKKSWLxoh/H9/EmqDFvNJ6qZzES8piXBf6YDGpdn4VCCFRoAOtbQoap8rc1P37TAWPCiMcLfWU0vNkvPG225Wsjd84q4aGWi0d5snoo9SP5a7guP5BNgiu2zgRaKqSaAZI1NKOoIaSKLk+Xyurvd48yj2e806bP9Hdj5m1rL1Wvt+Pz4hn+5onw+O0lrcOXrHLh9oeJPXiqz3G5p9YHDDEhXnXQYTRBrrM0xMrDtZ47AhoHQ6xz5ZtzR9GklisgVSU2lLFelt7uo73vLOVGfOxrbkej8Zv5fg3KAjWgWaeuNSqBkrh79D2AVNG6usVJj0LziltOWF4ONZE4Tu15GUExasPC6N8u35dIzPBYEyCHvzIfOFJ/UQc1HcCX0SZiydlVkGT00eZXHwRjsOXGoVgJrt981Fsp2os5IrP/jVuQ/e366Wn0wALTcZnZ3HPAbLKJSbLka8WaJyYWcX6MUZP4q6tv98thM67Jp0I9yWVJXq5gQBiCoDh8vKSnuy6gPmbpfnzsIg4I+plBxtRW9dwyjDb7zX0OQTqrRTqPYQJnRm/2uOWLzcMpeMpIxwKZCF4k1tyYCp+Oa0+eDed10458tpMiz3stWsewcnbd9Y1Rjeqt0FXMCW0mPdIBWaHPKhliSFhIHp45TC+E+c0dMcUncWXGlAcxGRcAwllTmwejw1uHoS7LqGvxaL7IgPDK9X8hhHqWob1jSW6p5/wiLwZyziDzK2llOzv/cxEHTCXMwqEMYGInEJDdjn2uPx6XOYd7B8KkM7KJB2sRfEAsNlZP0O8DWGR/iU/mNZzkyRcYL2ykN0k38q8mRZPVq7lKVvATNLVykvJRKrmjZ0kS+yu+gGKDUtc29V/FGAwoyDDvAWqWsAP6G2JF9qDoQZSkFjH8FXrdWwfdY30dnNpKekfGenmgMirOdIkvUeLnBO2T+IajKO1SLilx8Z0Wcs1N6cO6D+phCrIDLoH9R0ZhgJVmaweLEOopz+i99n+d5scyaJJikOC/lVz2+Bzh/GVEIjbwtCFZOilbfzc+uPrsFrbNewc7Kot5Z75o3g4aWJ35GswHC3rdB2FiCVc7m4DQilnSedKuqpKRprMR4ZPJf4YzOefw5ET1RWSiXoJAHRiNr2V+BQwK/EFJGITVbB1ZBCRpBSHYghSb5w0pSxSte1b8dlGZzQ19rdnA4Z66la4XWN7M2l3t4uS3QBwZ+558ReuluGXasQk8UIwI8FpJNACI8JKzP0O0vwqWEcGVpqO3AdZfjuuh31FREjkEBqPAdBmS7e2DMjwgW+OvaiBgzgQb4QRhuO5c9bfpx9Mb+cBVkY/kG3dSc1YlN5eZPa3cPn5JzNSGYH7moev5qa/wwJXmDjY5Btq3ZUgM2vUTSiN5vUmp9ZKmbHJHeO8xW+dob3vanb5SatC0HOJfYw+Ta6J3Zv1O+px4fWp3GefTymrbKP76tq9CPJk0d1n9FAbt3uZRyXTvH4bSL7oY+FJCA1TE1XGm9p1oktr7AhBrmyh6kjQoGYdHKczt5piCoZwp8ORe5joYTabkSW8w4mUsIbg6WHrT/GfYaChY6M=
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
X-Exchange-RoutingPolicyChecked: UuhNyhhiey0rJ77hA/Jb3fe36menoY+vTP2IAFNf+iDThsYg1X6Y272AfvXtdWyjDcZsUUSXciujnFEVE7lPJfXaTN9hTzYr+7s9Vnf76YZsRYub+dh+lofMTLaedFlBBtBbZOfn193ciDjLaVDBZ2jPAwcumGKInG8xG4YV0Q7dvKVCktAucLy6tQtexwKqSN526NUmWH0n7GkgGA++D0Zt/CUPQT0HcQvTTFJTY/ec58WaEMXVhUe3DLlmv0HiAQjN7iTKRiuTZHyv5CUbY+DcKjArWZcDh7y4JB54led6+o+9XAN25Tjlab5kM9ggvFADZUsdR3K4MQDYhuLT9A==
X-OriginatorOrg: orange.com
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: PAUP264MB6756.FRAP264.PROD.OUTLOOK.COM
X-MS-Exchange-CrossTenant-Network-Message-Id: 8ae82491-68f8-47c0-34bd-08deb5d03886
X-MS-Exchange-CrossTenant-originalarrivaltime: 19 May 2026 17:58:23.9124 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 90c7a20a-f34b-40bf-bc48-b9253b6f5d20
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: Y7b1XioW3pSCwqBDxSLFLn+6fpuT8x7WsV/g6S9EzR0dgEeW/Fpqujd6//xaniq5xNPlUAg+sOCqpqQT9GPFSgbWmmXPQ38GP6Zk4Scuroc=
X-MS-Exchange-Transport-CrossTenantHeadersStamped: PR0P264MB2257
X-TM-AS-ERS: 10.218.35.130-127.5.254.253
X-TM-AS-SMTP: 1.0 c210cC1vdXQzNjUub3JhbmdlLmNvbQ== bW9oYW1lZC5ib3VjYWRhaXJAb 3JhbmdlLmNvbQ==
X-TMASE-Version: DDEI-5.1-9.1.1004-29952.006
X-TMASE-Result: 10--40.829800-10.000000
X-TMASE-MatchedRID: u6ojmU07PKzaYagUwgwslPHkpkyUphL9F4r8H5YrEqxYC5LPd7BvbVxC 8wCAipyvMCPT7PzFeqzQJ4aXjIhjRK71lWFQP8hVARprIm1hk23La0eANE7Nz61iNb1cZnS8ILp NGVVgLcLVSDZW9GFolRTHwYepP0it139pJSwZBCXpKBIl/z0seP3Mwv7J07DXUXuzYZeRQl+wVK Rxy2EKZqr+x0bTLVd6ZAma8ZY88FS1XI2ULftjOC6L7gcGDBf4EHQQ1mfDW+1MaCZ02+qSX9LDV UadnwcMG7TQ2jAXIsnkyMcrb00CrEACpmTU52uUPkILbTHNp5v6UU2arQpzTUBeISr6o/bC245r wxPuiMcz3TJWI0hsNcWRKXEn1xwn7zP8XEBcvIKXVXMu1aPavK7YaZ2V2aJQHTMj5a5/7iabV4X +HXCyWc64IWk7CsDMpo0Zo841z+0HP2Rg4WNNPaEtILqFekmXm/t43d5OEX4EpmTf3u8rpe/m0b mpDCNAvzPc3wjAfhT3Nfz6ZKbpbrKMKAuc41QjQ0Xm0pWWLkre22ctUL9zM9Z5C2tydwt9xnUXz yseixwVnU2jzoZx1MzlOvZ73suzo7hUEb5WsJIAPmNKDWsW0CjhvSkr09hAK10GupkmZUvXDoAO DoFAbzWWmEiEjHW0fjWeJX0rKbNC/bXMk2XQLIMbH85DUZXyseWplitmp0j6C0ePs7A07YVH0dq 7wY7uA/3R8k/14e0=
X-TMASE-SNAP-Result: 1.821001.0001-0-1-22:0,33:0,34:0-0
X-TMASE-INERTIA: 0-0;;;;
X-TMASE-XGENCLOUD: NULL-NULL-7-0-1
Content-Transfer-Encoding: base64
Message-ID-Hash: AWXSCPT46NBCDT7XTBMOHLINKXTTCAPU
X-Message-ID-Hash: AWXSCPT46NBCDT7XTBMOHLINKXTTCAPU
X-MailFrom: mohamed.boucadair@orange.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-dnsop.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [DNSOP] Re: [v6ops] Corner-case in DNS authority guidance impacting IPv6-only resolvers
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/dnsop/xfomLgqmnVy_3RJfoJLNpTFGll4>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dnsop>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Owner: <mailto:dnsop-owner@ietf.org>
List-Post: <mailto:dnsop@ietf.org>
List-Subscribe: <mailto:dnsop-join@ietf.org>
List-Unsubscribe: <mailto:dnsop-leave@ietf.org>
Re- > @Med: How should we go about these process wise? Add a new > revision? No need to submit a new revision. What I have seen so far are minor clarifications and edits that can be passed to the RFC Editor during AUTH48. Once the discussion converges, I suggest that you summarize the OLD/NEW changes. Thank you. Cheers, Med > -----Message d'origine----- > De : Tobias Fiebig <tobias=40fiebig.nl@dmarc.ietf.org> > Envoyé : mardi 19 mai 2026 19:25 > À : dnsop@ietf.org > Objet : [DNSOP] Re: [v6ops] Corner-case in DNS authority guidance > impacting IPv6-only resolvers > > > Dear all, > > just reviewed these suggestions. Comments below. > > @Med: How should we go about these process wise? Add a new > revision? > > > > When providing multiple DNS servers to stub resolvers, > network > > > operators have to consider that, at the time of writing, > various > > > implementations can only configure a small set of possible DNS > > > resolvers, e.g., only up to three for libc [MAN], and > additional > > > resolvers provided may be ignored by clients. Hence, when > providing > > > more than three DNS servers to stub resolvers, operators > SHOULD > > > ensure that no more than two recursive DNS servers supplied to > > > clients are unable to perform dual-stack DNS resolution, and > at > > > least one of the supplied recursive DNS servers is able to > perform > > > dual-stack DNS resolution. If this is not done, a client might > > > select a subset of recursive DNS servers that leads to address > > > family based namespace fragmentation. > > > > with: > > > > > When providing multiple recursive DNS servers to stub > resolvers, > > > network operators have to consider that, at the time of > writing, > > > various implementations can only configure a small set of > possible > > > DNS resolver addresses, e.g., only up to three for libc [MAN], > and > > > additional resolver addresses provided may be non- > deterministically > > > ignored by clients. Hence, when providing more than three > recursive > > > server addresses to stub resolvers, operators SHOULD ensure > that > > > either 1) all supplied recursive server IPs are from the same > adress > > > family, based on knowledge as to clients being IPv4-only or > > > IPv6-mostly; or 2) exactly two IPs are from one address family > > > (IPv4 or IPv6) and exactly one is from the other address > family. > > > Furthermore, all suppled resolvers SHOULD be able to perform > dual- > > > stack DNS resolution to avoid address family based namespace > > > fragmentation. > > This looks reasonable to me. > > > > Similar to authoritative servers, (stub) recursive resolvers > may > > > face broken IP connectivity for either IPv4 or IPv6: > > > > The "(stub) recursive" should be replaced with "both stub and > > recursive" -- this is incorrect as currently written. > > The stub resolvers are what talk to the recursive resolvers and > each > > can independently have connectivity issues.. > > Works for me, would just adopt the suggestion. > > > It would also be worth seeing if we can use a different word for > > "fragmentation" > > in some contexts. Using "fragmentation" for both "IP > fragmentation" > > and "namespace fragmentation" > > is highly confusing to the reader. At a minimum we should > always > > qualify which form of fragmentation we are using and never use > > "fragmentation" by itself. Preferable might be to replace one > of them > > (eg, "namespace fragmentation" with "namespace divergence" or > > "namespace partitioning" or "namespace consistency"). > > > > This is especially the case in a section like "3.2. Network > Conditions > > Causing IP Address Family Related Name Space Fragmentation" > > as some of the reasons for Name Space Fragmentation are IP > > Fragmentation. > > (Name Space Fragmentation is a Layer 7 issue, IP Fragmentation > is a > > layer 3 issue.) > > I like namespace partitioning. This should, effectively, be an > editorial change, no? > > > > Consistency: Both IPv4 and IPv6 transports MUST serve > identical DNS > > > data to ensure a consistent resolution experience across > different > > > network types. > > > > This doesn't match against common practices for Global Traffic > > Management systems like CDNs that use the IP address to > determine what > > answer to provide. I'd strongly recommend switching to a > "SHOULD" > > (perhaps replacing "identical" with "equivalent"). > > I disagree with this one. A query to 2001:db8::53 with a client > subnet of 192.0.2.0/24 for A example.com should also receive the > same response as a query to 203.0.113.53 with a client subnet of > 192.0.2.0/24 for A example.com. > > In practice, however, this may (as you say) differ. > > The problem is that RFC1034 Sec. 4.1 somewhat implies this > consistency, while, IIRC, the above (even though lived practice) > has never been formalized; So, going away from the MUST feels a > bit like a too deep change. > > I would need more opinions on this. > > > The other proposed change to cover this thread would be in "4.1. > > Guidelines for Authoritative DNS Server Configuration" > > to add a sentence at the end of that section with: > > > > "When a recursive resolver queries for A or AAAA address > record > > that are missing (due to an authoritative nameserver having only > IPv4 > > or IPv6), a NODATA is received. To prevent resolution failures > or > > performance issues from recursive recursive having to hunt for a > > reachable DNS authority, the number of nameservers without both > > reachable IPv4 and IPv6 address records SHOULD be minimized." > > > > or: > > > > "When a recursive resolver queries for A or AAAA address > record > > that are missing (due to an authoritative nameserver having only > IPv4 > > or IPv6), a NODATA is received. To prevent resolution failures > or > > performance issues from recursive recursive having to hunt for a > > reachable DNS authority, all authoritative DNS nameservers > SHOULD be > > configured with both IPv4 and IPv6 address records." > > I would prefer the latter; But, again, I would really appreciate > some more thoughts on this. > > With best regards, > Tobias > > -- > Univ.Prof. Dr.-Ing. Tobias Fiebig > T +31 616 80 98 99 > M tobias@fiebig.at > > _______________________________________________ > DNSOP mailing list -- dnsop@ietf.org > To unsubscribe send an email to dnsop-leave@ietf.org ____________________________________________________________________________________________________________ Ce message et ses pieces jointes peuvent contenir des informations confidentielles ou privilegiees et ne doivent donc pas etre diffuses, exploites ou copies sans autorisation. Si vous avez recu ce message par erreur, veuillez le signaler a l'expediteur et le detruire ainsi que les pieces jointes. Les messages electroniques etant susceptibles d'alteration, Orange decline toute responsabilite si ce message a ete altere, deforme ou falsifie. Merci. This message and its attachments may contain confidential or privileged information that may be protected by law; they should not be distributed, used or copied without authorisation. If you have received this email in error, please notify the sender and delete this message and its attachments. As emails may be altered, Orange is not liable for messages that have been modified, changed or falsified. Thank you.
- [DNSOP] Corner-case in DNS authority guidance imp… Erik Nygren
- [DNSOP] Re: [v6ops] Corner-case in DNS authority … mohamed.boucadair
- [DNSOP] Re: [v6ops] Corner-case in DNS authority … Erik Nygren
- [DNSOP] Re: [v6ops] Corner-case in DNS authority … Erik Nygren
- [DNSOP] Re: [v6ops] Corner-case in DNS authority … Erik Nygren
- [DNSOP] Re: [v6ops] Corner-case in DNS authority … Tobias Fiebig
- [DNSOP] Re: [v6ops] Corner-case in DNS authority … Erik Nygren
- [DNSOP] Re: [v6ops] Corner-case in DNS authority … Tobias Fiebig
- [DNSOP] Re: [v6ops] Corner-case in DNS authority … mohamed.boucadair
- [DNSOP] Re: [v6ops] Corner-case in DNS authority … Erik Nygren