[mdnsext] mDNSext features/requirements rollup

Olivier Levon <mdnsext@levon.org> Wed, 30 January 2013 14:39 UTC

Return-Path: <olevon@gmail.com>
X-Original-To: mdnsext@ietfa.amsl.com
Delivered-To: mdnsext@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 6817721F8B35 for <mdnsext@ietfa.amsl.com>; Wed, 30 Jan 2013 06:39:30 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.376
X-Spam-Level:
X-Spam-Status: No, score=-2.376 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, FM_FORGED_GMAIL=0.622, HTML_MESSAGE=0.001, J_CHICKENPOX_13=0.6, RCVD_IN_DNSWL_LOW=-1]
Received: from mail.ietf.org ([64.170.98.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id zBZOIyuLZ2kL for <mdnsext@ietfa.amsl.com>; Wed, 30 Jan 2013 06:39:29 -0800 (PST)
Received: from mail-qc0-f178.google.com (mail-qc0-f178.google.com [209.85.216.178]) by ietfa.amsl.com (Postfix) with ESMTP id 77C4721F854D for <mdnsext@ietf.org>; Wed, 30 Jan 2013 06:39:29 -0800 (PST)
Received: by mail-qc0-f178.google.com with SMTP id j34so751718qco.37 for <mdnsext@ietf.org>; Wed, 30 Jan 2013 06:39:29 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=mime-version:x-received:sender:in-reply-to:references:date :x-google-sender-auth:message-id:subject:from:to:content-type; bh=B7Z1y9YCkqXU1j38E14a5pR6SljWxJDJuwhSjm/bNk0=; b=BnuMozjfrglEsEwb/Mu7W+XXIuvAUNRNnlPKiV27eWex1TK0yyEviHjBqfELUu3E1X YkLT2sGwteQjONx4471CC34G5+jvegR9phtm/kKhaDgPjfErq16z9eeqZjADS+t7TJga cTYssqyz0JC6rBgYGwUxe6Cm1qoj+dmngRbXp6Gq+mJz7uDDsNR5juakDicomj+CIK7a PNs2Xe2sZGvWrawm7+kwu1saE/zKcVFuY3pKu4BDrDPcIdi1IKVgaTL/weOT59OhGd1d R5Zx4VF+zUTQb1gtU0oGkePACC6iuqMfMTpx0vnMfxhVNmSJYSoSWhry1dNiBt5sVz6n Vw8Q==
MIME-Version: 1.0
X-Received: by 10.229.78.87 with SMTP id j23mr1234175qck.87.1359556768829; Wed, 30 Jan 2013 06:39:28 -0800 (PST)
Sender: olevon@gmail.com
Received: by 10.49.81.102 with HTTP; Wed, 30 Jan 2013 06:39:28 -0800 (PST)
In-Reply-To: <CAAGHepascKdeVp8VrD2XfsFzzEK3g4RA7VP0MM8DQ1bUh4VYVQ@mail.gmail.com>
References: <mailman.97.1359403423.10833.mdnsext@ietf.org> <D99048ACAF96354EBFD6A811E3C65ACD10977A7C@CH1PRD0811MB407.namprd08.prod.outlook.com> <1359484752.31527.140661184088257.2DD91FC3@webmail.messagingengine.com> <51082424.9090404@networkcommons.org> <CAAGHepa-1-tapDEYFSmLE851mHuCNF6xDn2afc+NdYVUqseiVQ@mail.gmail.com> <CAAGHepascKdeVp8VrD2XfsFzzEK3g4RA7VP0MM8DQ1bUh4VYVQ@mail.gmail.com>
Date: Wed, 30 Jan 2013 15:39:28 +0100
X-Google-Sender-Auth: XqB7CsM-QUdxc2VpXwZ7UgmEVfI
Message-ID: <CAAGHepYA=-sNpDRE4xCVCrYPmi+qiUn6kqgMMPvU4Ksyz=WmEQ@mail.gmail.com>
From: Olivier Levon <mdnsext@levon.org>
To: mdnsext@ietf.org
Content-Type: multipart/alternative; boundary="00235429c7bc42144b04d4827a86"
Subject: [mdnsext] mDNSext features/requirements rollup
X-BeenThere: mdnsext@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: "Discussion of extensions to Bonjour \(mDNS and DNS-SD\) for routed networks." <mdnsext.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/mdnsext>, <mailto:mdnsext-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/mdnsext>
List-Post: <mailto:mdnsext@ietf.org>
List-Help: <mailto:mdnsext-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/mdnsext>, <mailto:mdnsext-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 30 Jan 2013 14:40:20 -0000

Hi,

Some people did various patches to suport WAB in POSIX, like
http://www.roguelazer.com/tips/2010/02/dynamic-dns-part-two/ or
https://github.com/gkaindl/Community-mdnsResponder.
They were published on the bonjour-dev mailing list.

For my own use, I'm currently running my own patched version of POSIX
mdnsresponder on two Ubuntu boxes (one client with mdnsresponder and one
DNS server with dnsextd/bind).

Best,

Olivier

On Tue, Jan 29, 2013 at 8:33 PM, vortex <vortex@networkcommons.org> wrote:

>
> The problem has been that the POSIX and non-apple WAB component for
> read/write DNS-SD under the bonjour stack has been broken and ignored
> for years.
>
> Integrating mDNS & WAB has been close on impossible because of this
> (reference all the frustrations on the bonjour-dev mailing list without
> resolution, again, it's been years!).
>
> Alternate stacks such as avahi (non-cross platform) have waited for
> "vital" security implementations for DNSSEC before implementing write
> enabled DNS-SD (a big mistake IMHO!), and because DNSSEC is so hairy
> this has not happened either (on their roadmap unimplemented/delayed for
> years).
>
> WAB & m~DNS has had the potential to be an exciting cross platform
> Internet-wide resource publishing and discovery mechanism, but their
> seems little interest in the past to make this happen,
>
> Regards to all,
>
> .v
>
> On 29/01/2013 18:39, nudge wrote:
> > On Tue, Jan 29, 2013, at 07:07 PM, Alf Watt wrote:
> >>
> >> I think Andrew's point is worth taking the time to seriously consider.
> We
> >> already have dynamic DNS update but as previously mentioned
> configuration
> >> of the DNS server and it's clients out has proven to be either too
> >> difficult or not of interest to various OS vendors.
> >>
> >> It's worth mentioning that Apple has all the parts in place to pull this
> >> off:
> >>
> >> - A Server OS with an embedded DNS server which they provide a UI to
> >> manage
> >> - Traditional and Mobile Clients with mDNSResolvers running on them
> >> - A profile distribution system which make pushing configuration options
> >> including keys easy
> >>
> >> Given the will to get the features implemented Apple could solve part of
> >> the problem this without any changes to mdns.
> >>
> >> There are still things that fall outside of that scope which we should
> >> consider, but ignoring the opportunity to uses the existing protocols
> >> seems like a lot of effort to reproduce work that already exists.
> >>
> >> Best,
> >> Alf
> >>
> >
> > As someone who successfully tested and implemented WAB with TSIG
> > protected updates[1] in an Apple environment about a year or so ago, I
> > would tend to agree. It wasn't as difficult as I imagined partly because
> > of a lack of documentation. Of course, things have changed since and I
> > need to test again soon. But back then you had to front-end named with
> > dnsextd if you needed llq (obviously you do). If that's still true it
> > blocks other useful stuff such as rpz and rrl and needs fixing IMO.
> >
> > [1]I also tested TSIG protected reads DNSprivate, where's that going ?
> >
> > _______________________________________________
> > mdnsext mailing list
> > mdnsext@ietf.org
> > https://www.ietf.org/mailman/listinfo/mdnsext
> >
>
> _______________________________________________
> mdnsext mailing list
> mdnsext@ietf.org
> https://www.ietf.org/mailman/listinfo/mdnsext
>