Re: Last Call: 'Linklocal Multicast Name Resolution (LLMNR)' to Proposed Standard
Ian Jackson <ijackson@chiark.greenend.org.uk> Tue, 30 August 2005 10:33 UTC
Received: from localhost.localdomain ([127.0.0.1] helo=megatron.ietf.org) by megatron.ietf.org with esmtp (Exim 4.32) id 1EA3RB-0004Gw-VE; Tue, 30 Aug 2005 06:33:53 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org) by megatron.ietf.org with esmtp (Exim 4.32) id 1EA3R7-0004CR-IR for ietf@megatron.ietf.org; Tue, 30 Aug 2005 06:33:51 -0400
Received: from ietf-mx.ietf.org (ietf-mx [132.151.6.1]) by ietf.org (8.9.1a/8.9.1a) with ESMTP id GAA03733 for <ietf@ietf.org>; Tue, 30 Aug 2005 06:33:46 -0400 (EDT)
Received: from chiark.greenend.org.uk ([193.201.200.170] ident=mail) by ietf-mx.ietf.org with esmtp (Exim 4.43) id 1EA3Sd-0004nE-7L for ietf@ietf.org; Tue, 30 Aug 2005 06:35:24 -0400
Received: by chiark.greenend.org.uk (Debian Exim 3.35 #1) with local (return-path ijackson@chiark.greenend.org.uk) id 1EA3Qz-00086P-00; Tue, 30 Aug 2005 11:33:41 +0100
From: Ian Jackson <ijackson@chiark.greenend.org.uk>
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Message-ID: <17172.13829.578376.489917@chiark.greenend.org.uk>
Date: Tue, 30 Aug 2005 11:33:41 +0100
To: Brian E Carpenter <brc@zurich.ibm.com>
In-Reply-To: <43130559.5090503@zurich.ibm.com>
References: <200508260153.j7Q1rBPj000783@relay4.apple.com> <20050826072055.GA15833@nic.fr> <87ll2pkquy.fsf@windlord.stanford.edu> <430EFCFF.1010203@zurich.ibm.com> <17167.14936.141345.6653@chiark.greenend.org.uk> <43130559.5090503@zurich.ibm.com>
X-Mailer: VM 7.03 under Emacs 19.34.1
X-Spam-Score: 0.0 (/)
X-Scan-Signature: 244a2fd369eaf00ce6820a760a3de2e8
Content-Transfer-Encoding: 7bit
Cc: ietf@ietf.org
Subject: Re: Last Call: 'Linklocal Multicast Name Resolution (LLMNR)' to Proposed Standard
X-BeenThere: ietf@ietf.org
X-Mailman-Version: 2.1.5
Precedence: list
List-Id: IETF-Discussion <ietf.ietf.org>
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/ietf>, <mailto:ietf-request@ietf.org?subject=unsubscribe>
List-Post: <mailto:ietf@ietf.org>
List-Help: <mailto:ietf-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/ietf>, <mailto:ietf-request@ietf.org?subject=subscribe>
Sender: ietf-bounces@ietf.org
Errors-To: ietf-bounces@ietf.org
Brian E Carpenter writes ("Re: Last Call: 'Linklocal Multicast Name Resolution (LLMNR)' to Proposed Standard"): > Ian Jackson wrote: > > Sorry to be pejorative, but as a DNS implementor[1] I'm amazed to find > > senior IETF/IESG people seriously contemplating the kind of namespace > > confusion which is fundamental in the LLMNR protocol design. > > Can you spell that out please? Since it uses a different port number, > where does the confusion occur? What does the port number have to do with it ? That's an implementation detail (from the point of view of this complaint; many other complaints might well be about these kind of details). The LLMNR model supposes that when an application asks for data of a certain type associated with a certain name (ie, when the application thinks it's asking for a DNS query) answers may come from either the real DNS system or, even if the real DNS is authoritative for the relevant name but denies that it exists, from LLMNR. See draft-ietf-dnsext-mdns-42 s2 bullet point [2]. It is not true that separating LLMNR out on a different port, and introducing other incompatibilities, prevents confusion between LLMNR and the real DNS. Applications will still see a bizarre mix of real and LLMNR data. On the other hand, mDNS has a much better scheme: the mDNS specification defines the tree under `.local' for mDNS use. Names in .local are looked up with mDNS and names elsewhere via the real DNS. This means that applications always either see the data intended for them, or (transient) failure if the relevant mechanism isn't available. Stuart Cheshire makes IMO a very cogent argument in <200508251931.j7PJV7aR006028@relay4.apple.com>, where he says: ] What's weird about LLMNR is that it blurs what's global and what's local. ] With LLMNR you can call your television "tv.ietf.org" if you want, and as ] long as the IETF's name server returns NXDOMAIN (which it does today) ] then a LLMNR-compliant host will fail over to local multicast and resolve ] that name to your television's address. This sends a very strange message ] to end users -- it suggests they can use any name they want in any domain ] they want without having to communicate with any registry. It also means ] that every failed DNS query will result in a LLMNR multicast on the local ] network, and (worse) every intentional LLMNR query needs to be preceded ] by a failed DNS query to some unsuspecting DNS server somewhere. ] ] mDNS says that "local" is a free-for-all playground where anyone can use ] any name and no one has any more right to a particular name than anyone ] else. LLMNR didn't want to do that, but what they've effectively ended up ] doing instead is saying that the root of the DNS namespace (and ] everything below it) is a free-for-all playground where anyone can use ] any name they want. In addition, mDNS's limitation to `.local' means that deliberate additional incompatibilities to avoid cache pollution in the real DNS is not necessary; since mDNS is only used for names in `.local', normal precuations against unsolicited DNS replies will prevent the main DNS namespace being polluted with mDNS data. If we are to so strongly fear pollution, mDNS's wide deployment ought to provide some evidence for this from operational experience ! Where is that evidence ? Ian. _______________________________________________ Ietf mailing list Ietf@ietf.org https://www1.ietf.org/mailman/listinfo/ietf
- Re: Last Call: 'Linklocal Multicast Name Resoluti… Stuart Cheshire
- Re: Last Call: 'Linklocal Multicast Name Resoluti… Peter Dambier
- Re: Last Call: 'Linklocal Multicast Name Resoluti… Margaret Wasserman
- Re: Last Call: 'Linklocal Multicast Name Resoluti… Stuart Cheshire
- Re: Last Call: 'Linklocal Multicast Name Resoluti… Harald Tveit Alvestrand
- Re: Last Call: 'Linklocal Multicast Name Resoluti… Marc Manthey
- Re: Last Call: 'Linklocal Multicast Name Resoluti… Stuart Cheshire
- Re: Last Call: 'Linklocal Multicast Name Resoluti… Peter Dambier
- Re: Last Call: 'Linklocal Multicast Name Resoluti… Keith Moore
- Re: Last Call: 'Linklocal Multicast Name Resoluti… Peter Dambier
- Re: Last Call: 'Linklocal Multicast Name Resoluti… Margaret Wasserman
- Re: Last Call: 'Linklocal Multicast Name Resoluti… Stuart Cheshire
- Re: Last Call: 'Linklocal Multicast Name Resoluti… Stuart Cheshire
- Re: Last Call: 'Linklocal Multicast Name Resoluti… Stuart Cheshire
- Re: Last Call: 'Linklocal Multicast Name Resoluti… Margaret Wasserman
- Re: Last Call: 'Linklocal Multicast Name Resoluti… Margaret Wasserman
- Re: Last Call: 'Linklocal Multicast Name Resoluti… Stephane Bortzmeyer
- Re: Last Call: 'Linklocal Multicast Name Resoluti… Marc Manthey
- Re: Last Call: 'Linklocal Multicast Name Resoluti… Stephane Bortzmeyer
- Re: Last Call: 'Linklocal Multicast Name Resoluti… Russ Allbery
- Re: Last Call: 'Linklocal Multicast Name Resoluti… Brian E Carpenter
- Re: Last Call: 'Linklocal Multicast Name Resoluti… Bill Manning
- Re: Last Call: 'Linklocal Multicast Name Resoluti… Marshall Eubanks
- Re: Last Call: 'Linklocal Multicast Name Resoluti… Keith Moore
- Re: Last Call: 'Linklocal Multicast Name Resoluti… Ian Jackson
- Re: Last Call: 'Linklocal Multicast Name Resoluti… Iljitsch van Beijnum
- Re: Last Call: 'Linklocal Multicast Name Resoluti… Russ Allbery
- Re: Last Call: 'Linklocal Multicast Name Resoluti… Bill Manning
- Re: Last Call: 'Linklocal Multicast Name Resoluti… Rob Austein
- Re: Last Call: 'Linklocal Multicast Name Resoluti… Marc Manthey
- Re: Last Call: 'Linklocal Multicast Name Resoluti… Steven M. Bellovin
- Re: Last Call: 'Linklocal Multicast Name Resoluti… Pete Resnick
- Re: Last Call: 'Linklocal Multicast Name Resoluti… bmanning
- Re: Last Call: 'Linklocal Multicast Name Resoluti… Brian E Carpenter
- Re: Last Call: 'Linklocal Multicast Name Resoluti… Peter Dambier
- Re: Last Call: 'Linklocal Multicast Name Resoluti… Russ Allbery
- Re: Last Call: 'Linklocal Multicast Name Resoluti… Ian Jackson
- Re: Last Call: 'Linklocal Multicast Name Resoluti… Peter Dambier
- Re: Last Call: 'Linklocal Multicast Name Resoluti… Brian E Carpenter
- Re: Last Call: 'Linklocal Multicast Name Resoluti… Stuart Cheshire
- Re: Last Call: 'Linklocal Multicast Name Resoluti… Stuart Cheshire
- Re: Last Call: 'Linklocal Multicast Name Resoluti… Margaret Wasserman
- Re: Last Call: 'Linklocal Multicast Name Resoluti… Peter Dambier
- RE: Last Call: 'Linklocal Multicast Name Resoluti… Christian Huitema
- Re: Last Call: 'Linklocal Multicast Name Resoluti… Margaret Wasserman
- Re: Last Call: 'Linklocal Multicast Name Resoluti… Stuart Cheshire
- Re: Last Call: 'Linklocal Multicast Name Resoluti… Peter Dambier
- Re: Last Call: 'Linklocal Multicast Name Resoluti… Iljitsch van Beijnum
- Re: Last Call: 'Linklocal Multicast Name Resoluti… Ned Freed
- Re: Last Call: 'Linklocal Multicast Name Resoluti… Russ Allbery
- Re: Last Call: 'Linklocal Multicast Name Resoluti… Russ Allbery
- Re: Last Call: 'Linklocal Multicast Name Resoluti… Iljitsch van Beijnum
- Re: Last Call: 'Linklocal Multicast Name Resoluti… Jeffrey Hutzelman
- Re: Last Call: 'Linklocal Multicast Name Resoluti… Spencer Dawkins
- Re: Last Call: 'Linklocal Multicast Name Resoluti… Henrik Levkowetz
- Re: Last Call: 'Linklocal Multicast Name Resoluti… Peter Dambier
- Re: Last Call: 'Linklocal Multicast Name Resoluti… Bill Manning
- Re: Last Call: 'Linklocal Multicast Name Resoluti… Marc Manthey
- Re: Last Call: 'Linklocal Multicast Name Resoluti… Brian E Carpenter
- Re: Last Call: 'Linklocal Multicast Name Resoluti… Steven M. Bellovin
- Re: Last Call: 'Linklocal Multicast Name Resoluti… Jeroen Massar
- Re: Last Call: 'Linklocal Multicast Name Resoluti… Brian E Carpenter
- Re: Last Call: 'Linklocal Multicast Name Resoluti… Peter Dambier
- Re: Last Call: 'Linklocal Multicast Name Resoluti… Peter Dambier
- Re: Last Call: 'Linklocal Multicast Name Resoluti… Peter Dambier
- Single DNS root (Re: Last Call: 'Linklocal Multic… Harald Tveit Alvestrand
- RE: Last Call: 'Linklocal Multicast Name Resoluti… Christian Huitema
- Alternative roots (was: Re: Last Call: 'Linklocal… Paul Hoffman
- Re: Last Call: 'Linklocal Multicast Name Resoluti… Paul Hoffman
- Re: Last Call: 'Linklocal Multicast Name Resoluti… Christian de Larrinaga
- Re: Last Call: 'Linklocal Multicast Name Resoluti… Eric A. Hall
- Re: Last Call: 'Linklocal Multicast Name Resoluti… Ned Freed
- Re: Last Call: 'Linklocal Multicast Name Resoluti… Ned Freed
- Re: Last Call: 'Linklocal Multicast Name Resoluti… Eric A. Hall
- Re: Last Call: 'Linklocal Multicast Name Resoluti… Ian Jackson
- Re: Last Call: 'Linklocal Multicast Name Resoluti… Peter Dambier
- Re: Last Call: 'Linklocal Multicast Name Resoluti… Ned Freed
- Re: Last Call: 'Linklocal Multicast Name Resoluti… Ian Jackson
- RE: Last Call: 'Linklocal Multicast Name Resoluti… Ian Jackson
- Re: Last Call: 'Linklocal Multicast Name Resoluti… Tony Finch
- RE: Last Call: 'Linklocal Multicast Name Resoluti… Stuart Cheshire
- RE: Last Call: 'Linklocal Multicast Name Resoluti… Christian Huitema
- RE: Last Call: 'Linklocal Multicast Name Resoluti… Dave Singer
- Re: Single DNS root JFC (Jefsey) Morfin
- Re: Last Call: 'Linklocal Multicast Name Resoluti… Keith Moore
- RE: Last Call: 'Linklocal Multicast Name Resoluti… Jeroen Massar
- Re: Last Call: 'Linklocal Multicast Name Resoluti… Frank Ellermann
- Re: Last Call: 'Linklocal Multicast Name Resoluti… Jeroen Massar
- Name ownership and LLMNR (Re: Last Call: 'Linkloc… Harald Tveit Alvestrand
- Re: Last Call: 'Linklocal Multicast Name Resoluti… Ian Jackson
- Re: Last Call: 'Linklocal Multicast Name Resoluti… Peter Dambier
- Re: Last Call: 'Linklocal Multicast Name Resoluti… Peter Dambier
- Re: Last Call: 'Linklocal Multicast Name Resoluti… Keith Moore
- Re: Last Call: 'Linklocal Multicast Name Resoluti… Henning Schulzrinne
- Re: Last Call: 'Linklocal Multicast Name Resoluti… Iljitsch van Beijnum
- Re: Name ownership and LLMNR (Re: Last Call: 'Lin… Tony Finch
- Re: Last Call: 'Linklocal Multicast Name Resoluti… Alan Barrett
- Re: Name ownership and LLMNR (Re: Last Call: 'Lin… Iljitsch van Beijnum
- Re: Last Call: 'Linklocal Multicast Name Resoluti… Tony Finch
- Re: Last Call: 'Linklocal Multicast Name Resoluti… Paul Vixie
- Re: Last Call: 'Linklocal Multicast Name Resoluti… Stephane Bortzmeyer
- Re: Last Call: 'Linklocal Multicast Name Resoluti… Paul Vixie
- Re: Last Call: 'Linklocal Multicast Name Resoluti… Ian Jackson
- Re: Name ownership and LLMNR (Re: Last Call: 'Lin… Harald Tveit Alvestrand
- Re: Name ownership and LLMNR (Re: Last Call: 'Lin… Jeroen Massar
- Re: Name ownership and LLMNR (Re: Last Call: 'Lin… Iljitsch van Beijnum
- Re: Single DNS root John C Klensin
- Re: Name ownership and LLMNR (Re: Last Call: 'Lin… Daniel Senie
- Re: Name ownership and LLMNR (Re: Last Call: 'Lin… Jeffrey Hutzelman
- Re: Name ownership and LLMNR (Re: Last Call: 'Lin… Harald Tveit Alvestrand
- Re: Name ownership and LLMNR (Re: Last Call: 'Lin… Iljitsch van Beijnum
- Re: Name ownership and LLMNR (Re: Last Call: 'Lin… Bill Manning
- Re: Single DNS root JFC (Jefsey) Morfin
- Re: Name ownership and LLMNR (Re: Last Call: 'Lin… Tony Finch
- Re: Name ownership and LLMNR (Re: Last Call: 'Lin… Steven M. Bellovin
- Re: Name ownership and LLMNR (Re: Last Call: 'Lin… Tony Finch
- Re: Name ownership and LLMNR (Re: Last Call: 'Lin… Masataka Ohta
- Re: Last Call: 'Linklocal Multicast Name Resoluti… JFC (Jefsey) Morfin
- Re: Name ownership and LLMNR (Re: Last Call: 'Lin… Harald Tveit Alvestrand
- Re: Last Call: 'Linklocal Multicast Name Resoluti… Daniel Karrenberg
- Re: Name ownership and LLMNR (Re: Last Call: 'Lin… JFC (Jefsey) Morfin
- Re: Last Call: 'Linklocal Multicast Name Resoluti… Andrew Sullivan
- RE: Last Call: 'Linklocal Multicast Name Resoluti… Stuart Cheshire