Re: [v6ops] NAT64/DNS64 and DNSSEC

Philip Homburg <pch-v6ops-3@u-1.phicoh.com> Thu, 23 July 2015 08:42 UTC

Return-Path: <pch-bBB316E3E@u-1.phicoh.com>
X-Original-To: v6ops@ietfa.amsl.com
Delivered-To: v6ops@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 7637B1A8ABD for <v6ops@ietfa.amsl.com>; Thu, 23 Jul 2015 01:42:24 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.6
X-Spam-Level:
X-Spam-Status: No, score=-4.6 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, GB_I_LETTER=-2, RCVD_IN_DNSWL_LOW=-0.7] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Fa4xzjxXlJEE for <v6ops@ietfa.amsl.com>; Thu, 23 Jul 2015 01:42:22 -0700 (PDT)
Received: from stereo.hq.phicoh.net (stereo.hq.phicoh.net [130.37.15.35]) by ietfa.amsl.com (Postfix) with ESMTP id 116201A1BE4 for <v6ops@ietf.org>; Thu, 23 Jul 2015 01:41:30 -0700 (PDT)
Received: from stereo.hq.phicoh.net (localhost [::ffff:127.0.0.1]) by stereo.hq.phicoh.net with esmtp (Smail #91) id m1ZIC4H-0000CdC; Thu, 23 Jul 2015 10:41:29 +0200
Message-Id: <m1ZIC4H-0000CdC@stereo.hq.phicoh.net>
To: v6ops@ietf.org
From: Philip Homburg <pch-v6ops-3@u-1.phicoh.com>
Sender: pch-bBB316E3E@u-1.phicoh.com
In-reply-to: Your message of "Thu, 23 Jul 2015 09:13:26 +0200 (CEST) ." <alpine.DEB.2.02.1507230910190.11810@uplift.swm.pp.se>
Date: Thu, 23 Jul 2015 10:41:28 +0200
Archived-At: <http://mailarchive.ietf.org/arch/msg/v6ops/K61VlmnVvCHIH4P0fZXjE7En7Dg>
Subject: Re: [v6ops] NAT64/DNS64 and DNSSEC
X-BeenThere: v6ops@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: v6ops discussion list <v6ops.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/v6ops>, <mailto:v6ops-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/v6ops/>
List-Post: <mailto:v6ops@ietf.org>
List-Help: <mailto:v6ops-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/v6ops>, <mailto:v6ops-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 23 Jul 2015 08:42:24 -0000

In your letter dated Thu, 23 Jul 2015 09:13:26 +0200 (CEST) you wrote:
>as far as I know, DNS64 and DNSSEC are fundamentally incompatible, because 
>modifying A records into AAAA records breaks DNSSEC.

My conclusion is that essentially you have to do 464XLAT if the network
does NAT64.

That way you can have IPv4 literals and you can run unmodified DNS.