RE: (ngtrans) Last call on draft-ietf-ngtrans-dns-ops-req-02.txt

Pekka Savola <pekkas@netcore.fi> Sun, 21 October 2001 15:49 UTC

Received: from patan.sun.com (patan.Sun.COM [192.18.98.43]) by ietf.org (8.9.1a/8.9.1a) with ESMTP id LAA14637 for <ngtrans-archive@odin.ietf.org>; Sun, 21 Oct 2001 11:49:53 -0400 (EDT)
Received: from engmail1.Eng.Sun.COM ([129.146.1.13]) by patan.sun.com (8.9.3+Sun/8.9.3) with ESMTP id JAA05471; Sun, 21 Oct 2001 09:48:33 -0600 (MDT)
Received: from sunroof.eng.sun.com (sunroof.Eng.Sun.COM [129.146.168.88]) by engmail1.Eng.Sun.COM (8.9.3+Sun/8.9.3/ENSMAIL,v2.1p1) with ESMTP id IAA28991; Sun, 21 Oct 2001 08:48:34 -0700 (PDT)
Received: from sunroof.eng.sun.com (localhost [127.0.0.1]) by sunroof.eng.sun.com (8.12.1+Sun/8.12.1) with ESMTP id f9LFmCOI004166 for <ngtrans-dist@sunroof.eng.sun.com>; Sun, 21 Oct 2001 08:48:12 -0700 (PDT)
Received: (from majordomo@localhost) by sunroof.eng.sun.com (8.12.1+Sun/8.12.1/Submit) id f9LFmBnY004165 for ngtrans-dist; Sun, 21 Oct 2001 08:48:11 -0700 (PDT)
X-Authentication-Warning: sunroof.eng.sun.com: majordomo set sender to owner-ngtrans@sunroof.eng.sun.com using -f
Received: from engmail4.Eng.Sun.COM (engmail4 [129.144.134.6]) by sunroof.eng.sun.com (8.12.1+Sun/8.12.1) with ESMTP id f9LFm9OI004158 for <ngtrans@sunroof.eng.sun.com>; Sun, 21 Oct 2001 08:48:09 -0700 (PDT)
Received: from saturn.sun.com (saturn.EBay.Sun.COM [129.150.69.2]) by engmail4.Eng.Sun.COM (8.9.3+Sun/8.9.3/ENSMAIL, v2.1p1) with ESMTP id IAA04981 for <ngtrans@sunroof.eng.sun.com>; Sun, 21 Oct 2001 08:48:03 -0700 (PDT)
Received: from netcore.fi (netcore.fi [193.94.160.1]) by saturn.sun.com (8.9.3+Sun/8.9.3) with ESMTP id IAA29042 for <ngtrans@sunroof.eng.sun.com>; Sun, 21 Oct 2001 08:48:10 -0700 (PDT)
Received: from localhost (pekkas@localhost) by netcore.fi (8.11.6/8.11.6) with ESMTP id f9LFm6720929; Sun, 21 Oct 2001 18:48:06 +0300
Date: Sun, 21 Oct 2001 18:48:06 +0300
From: Pekka Savola <pekkas@netcore.fi>
To: Randy Bush <randy@psg.com>
cc: ngtrans@sunroof.eng.sun.com
Subject: RE: (ngtrans) Last call on draft-ietf-ngtrans-dns-ops-req-02.txt
In-Reply-To: <E15vKXf-0005yc-00@rip.psg.com>
Message-ID: <Pine.LNX.4.33.0110211831510.20859-100000@netcore.fi>
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset="US-ASCII"
Sender: owner-ngtrans@sunroof.eng.sun.com
Precedence: bulk
Reply-To: Pekka Savola <pekkas@netcore.fi>

On Sun, 21 Oct 2001, Randy Bush wrote:
> >> the task of this wg is to develop strategies and techniques for
> >> transitioning from a pure v4 internet to a mostly v6 internet over
> >> a period of a long time, i.e. a decade or N.  in the solution
> >> space, it is not reasonable for there to be one or more partitions
> >> where internet hostsand running v4 can not locate and reach
> >> internet hosts running v6 or vice versa.
> > But the questions (that haven't been answered properly, or asked for that
> > matter) are, "does this have to be done now?" and "do we know _yet_ that
> > this approach is the best one in the long run?").
> 
> this is not an 'approach', i.e. solution, tool, ...  it is a requirement.

There seem to be some hints for a certain approach in itself, for example:

--8<--
   The IPv6 resolver MUST have a way to discover the bridging systems.
   This discovery mechanism MUST also have good scaling properties.
--8<--

This seems to require that every IPv6 resolving node must be able to do
the discovery; the discovery cannot be "delegated" to certain (type-of, 
possibly) servers.

Using the word "discover" hints at non-manual configuration (e.g.  
anycast).

--8<--
7. Security considerations


   Any bridging system, acting as open relay, could be misused to create
   denial of service attacks on external DNS servers.  Some provision
   should be made in the design of those relay to deal with this issue.
--8<--

This is nothing new and can be done today with about any DNS server (e.g. 
request recursion).

-- 
Pekka Savola                 "Tell me of difficulties surmounted,
Netcore Oy                   not those you stumble over and fall"
Systems. Networks. Security.  -- Robert Jordan: A Crown of Swords