Re: [DNSOP] [EXT] Re: [Technical Errata Reported] RFC7686 (6761)

Mark Andrews <marka@isc.org> Wed, 01 December 2021 01:40 UTC

Return-Path: <marka@isc.org>
X-Original-To: dnsop@ietfa.amsl.com
Delivered-To: dnsop@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 9DD1E3A07EB for <dnsop@ietfa.amsl.com>; Tue, 30 Nov 2021 17:40:26 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.099
X-Spam-Level:
X-Spam-Status: No, score=-2.099 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=isc.org header.b=NTCKJudh; dkim=pass (1024-bit key) header.d=isc.org header.b=H+9dmpKe
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id gWkroy5SCJIC for <dnsop@ietfa.amsl.com>; Tue, 30 Nov 2021 17:40:22 -0800 (PST)
Received: from mx.pao1.isc.org (mx.pao1.isc.org [IPv6:2001:4f8:0:2::2b]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 399BF3A07F3 for <dnsop@ietf.org>; Tue, 30 Nov 2021 17:40:22 -0800 (PST)
Received: from zimbrang.isc.org (zimbrang.isc.org [149.20.1.12]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client did not present a certificate) by mx.pao1.isc.org (Postfix) with ESMTPS id B4A91435948; Wed, 1 Dec 2021 01:40:20 +0000 (UTC)
DKIM-Signature: v=1; a=rsa-sha256; c=simple/simple; d=isc.org; s=ostpay; t=1638322820; bh=6nHp7zZerG9Ujm7RThJwZV5IKKm0LE7ei/ElQiHvgc8=; h=Subject:From:In-Reply-To:Date:Cc:References:To; b=NTCKJudhB0WWyVDsNn6FTElB+ctk4ereG0jYU6XbwQR09Mr4olPdLfsoQ8G3djkYB rqv5eH4re8L06IRwJYXHBVyRIvktIfXNNuTfQwMM7XGcTgcA3N7IZIN9YlhkjiaVVm mwicnLKWGMPbBu1kI3fRTrUHTQoO7wLwbQB2+yO4=
Received: from zimbrang.isc.org (localhost.localdomain [127.0.0.1]) by zimbrang.isc.org (Postfix) with ESMTPS id A4F4CF25349; Wed, 1 Dec 2021 01:40:20 +0000 (UTC)
Received: from localhost (localhost.localdomain [127.0.0.1]) by zimbrang.isc.org (Postfix) with ESMTP id 76824F25389; Wed, 1 Dec 2021 01:40:20 +0000 (UTC)
DKIM-Filter: OpenDKIM Filter v2.10.3 zimbrang.isc.org 76824F25389
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=isc.org; s=05DFB016-56A2-11EB-AEC0-15368D323330; t=1638322820; bh=sl/vSad/77gSWrLLzKuoyZeobHrCL8SR+vbexFZX8Ak=; h=Mime-Version:From:Date:Message-Id:To; b=H+9dmpKeR4noyhIllAizR149S77G1U7ZEBMr0z+u07uc7vOfA/3dAEIMLloYmcR3m IBVHv+dGxBz4gWjjoFfx8SBtJDQSzzNCXrS4mHLnburm03pspIdxOtZW6tAwjMPmpH f/Y69jsD8li1QVgqnalrQ8wsgk94k1uYLfJwDQb0=
Received: from zimbrang.isc.org ([127.0.0.1]) by localhost (zimbrang.isc.org [127.0.0.1]) (amavisd-new, port 10026) with ESMTP id uEmXmy7e_8wB; Wed, 1 Dec 2021 01:40:20 +0000 (UTC)
Received: from smtpclient.apple (n114-74-30-70.bla4.nsw.optusnet.com.au [114.74.30.70]) by zimbrang.isc.org (Postfix) with ESMTPSA id 7444BF25349; Wed, 1 Dec 2021 01:40:19 +0000 (UTC)
Content-Type: text/plain; charset=utf-8
Mime-Version: 1.0 (Mac OS X Mail 14.0 \(3654.120.0.1.13\))
From: Mark Andrews <marka@isc.org>
In-Reply-To: <b149b55e-1385-9907-0695-f780b469464c@redbarn.org>
Date: Wed, 1 Dec 2021 12:40:16 +1100
Cc: Ted Lemon <mellon@fugue.com>, dnsop@ietf.org, "libor.peltan" <libor.peltan@nic.cz>
Content-Transfer-Encoding: quoted-printable
Message-Id: <AEE90C9C-0575-44E3-9D51-1B0FCE7D484F@isc.org>
References: <20211129190711.E4E9B36417@rfc-editor.org> <19c96ba9-a582-a24-b73-8e86a08c7b68@nohats.ca> <794d45f4b9093a019b94aee4730161d358b5ba79.camel@powerdns.com> <198228F8-F970-47E3-8690-5B13FB324231@hopcount.ca> <d3957532-33e8-f79f-a94f-8775948c886b@iecc.com> <28d5129a-b543-7d65-6d91-c87b421bbe1c@nic.cz> <d666dd21-10b2-c8d2-16b8-c5c723712613@redbarn.org> <9dacfae6-0dca-8687-466a-6ce20b7d9e88@nic.cz> <CAPt1N1nei=QUcXji9XqD5q75XQnNYkn5ZEWMoJs6k_OahdOSUA@mail.gmail.com> <b149b55e-1385-9907-0695-f780b469464c@redbarn.org>
To: Paul Vixie <paul=40redbarn.org@dmarc.ietf.org>
X-Mailer: Apple Mail (2.3654.120.0.1.13)
Archived-At: <https://mailarchive.ietf.org/arch/msg/dnsop/yqCKffLwdrGtjVp-I8KCZQCh9O0>
Subject: Re: [DNSOP] [EXT] Re: [Technical Errata Reported] RFC7686 (6761)
X-BeenThere: dnsop@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dnsop>, <mailto:dnsop-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dnsop/>
List-Post: <mailto:dnsop@ietf.org>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dnsop>, <mailto:dnsop-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 01 Dec 2021 01:40:27 -0000

Authoritative servers should take NO SPECIAL BEHAVIOUR for .onion.

The default behaviour of an authoritative server is fine be it REFUSED,
NOTAUTH, NXDOMAIN (when they have a copy of the root zone) or a referral
to the root.

Recursive servers are a different kettle of fish.

Mark

> On 1 Dec 2021, at 12:10, Paul Vixie <paul=40redbarn.org@dmarc.ietf.org> wrote:
> 
> 
> 
> Ted Lemon wrote on 2021-11-30 17:04:
>> I don’t see how any answer from an authoritative server other than REFUSED really makes sense for a domain for which that server is not authoritative. It hasn’t failed. It’s been asked a bogus question. It doesn’t make sense for it to theorize that it might be misconfigured.
> 
> i only use REFUSED if the same question from some other query source (by IP) or signed differently (with TSIG or SIG(0)) could possibly work. for out-of-authority requests, the server must fail to answer.
> 
> _______________________________________________
> DNSOP mailing list
> DNSOP@ietf.org
> https://www.ietf.org/mailman/listinfo/dnsop

-- 
Mark Andrews, ISC
1 Seymour St., Dundas Valley, NSW 2117, Australia
PHONE: +61 2 9871 4742              INTERNET: marka@isc.org