Re: [DNSOP] RFC7720 and AXFR

Evan Hunt <each@isc.org> Sun, 28 October 2018 17:54 UTC

Return-Path: <each@isc.org>
X-Original-To: dnsop@ietfa.amsl.com
Delivered-To: dnsop@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id BCB78124408 for <dnsop@ietfa.amsl.com>; Sun, 28 Oct 2018 10:54:32 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -6.901
X-Spam-Level:
X-Spam-Status: No, score=-6.901 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_HI=-5, SPF_PASS=-0.001] autolearn=unavailable autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id HMRpxpnKDJJ5 for <dnsop@ietfa.amsl.com>; Sun, 28 Oct 2018 10:54:31 -0700 (PDT)
Received: from mx.pao1.isc.org (mx.pao1.isc.org [149.20.64.53]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id AE124128A5C for <dnsop@ietf.org>; Sun, 28 Oct 2018 10:46:56 -0700 (PDT)
Received: from bikeshed.isc.org (bikeshed.isc.org [IPv6:2001:4f8:3:d::19]) (using TLSv1 with cipher DHE-RSA-CAMELLIA256-SHA (256/256 bits)) (No client certificate requested) by mx.pao1.isc.org (Postfix) with ESMTPS id EFC5C3AB03B; Sun, 28 Oct 2018 17:46:45 +0000 (UTC)
Received: by bikeshed.isc.org (Postfix, from userid 10292) id 63484216C1C; Sun, 28 Oct 2018 17:46:41 +0000 (UTC)
Date: Sun, 28 Oct 2018 17:46:41 +0000
From: Evan Hunt <each@isc.org>
To: Grant Taylor <gtaylor=40tnetconsulting.net@dmarc.ietf.org>
Cc: dnsop@ietf.org
Message-ID: <20181028174641.GA22526@isc.org>
References: <2c00abd8-1c0d-cfee-5a5f-764a90f3f38c@andreasschulze.de> <20181028164441.GA22119@isc.org> <11f5c334-dc1a-07c0-e1b2-d7213be278d3@spamtrap.tnetconsulting.net>
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Disposition: inline
In-Reply-To: <11f5c334-dc1a-07c0-e1b2-d7213be278d3@spamtrap.tnetconsulting.net>
User-Agent: Mutt/1.5.23 (2014-03-12)
Archived-At: <https://mailarchive.ietf.org/arch/msg/dnsop/zd6sd5eKn_CG9Qz1kiWPvCdC_20>
Subject: Re: [DNSOP] RFC7720 and AXFR
X-BeenThere: dnsop@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dnsop>, <mailto:dnsop-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dnsop/>
List-Post: <mailto:dnsop@ietf.org>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dnsop>, <mailto:dnsop-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sun, 28 Oct 2018 17:54:33 -0000

On Sun, Oct 28, 2018 at 11:05:17AM -0600, Grant Taylor wrote:
> Does root zone local mirroring require that the zone comes from the 
> lettered root servers themselves?  Or could it come from another server 
> with the root zone?  Possibly a server that one or more operators set up 
> specifically for the purpose?

You're right, it could, and I'd forgotten earlier that the appendix
does also mention lax.xfr.dns.icann.org and iad.xfr.dns.icann.org.

However, the root servers are the root servers. We all know A through M by
heart, and resolvers have their addresses built in and kept up to date.
Seems like a useful thing to leverage, if possible.

-- 
Evan Hunt -- each@isc.org
Internet Systems Consortium, Inc.