Re: [v6ops] NAT64/DNS64 and DNSSEC

Erik Kline <ek@google.com> Wed, 29 July 2015 14:11 UTC

Return-Path: <ek@google.com>
X-Original-To: v6ops@ietfa.amsl.com
Delivered-To: v6ops@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 1B7BD1A1BDD for <v6ops@ietfa.amsl.com>; Wed, 29 Jul 2015 07:11:53 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -0.789
X-Spam-Level:
X-Spam-Status: No, score=-0.789 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FM_FORGED_GMAIL=0.622, J_CHICKENPOX_14=0.6, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id asxE4zYaS4L6 for <v6ops@ietfa.amsl.com>; Wed, 29 Jul 2015 07:11:52 -0700 (PDT)
Received: from mail-wi0-x22f.google.com (mail-wi0-x22f.google.com [IPv6:2a00:1450:400c:c05::22f]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id A57771A1EF3 for <v6ops@ietf.org>; Wed, 29 Jul 2015 07:11:51 -0700 (PDT)
Received: by wibxm9 with SMTP id xm9so28399416wib.1 for <v6ops@ietf.org>; Wed, 29 Jul 2015 07:11:50 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20120113; h=mime-version:in-reply-to:references:from:date:message-id:subject:to :cc:content-type:content-transfer-encoding; bh=MSqa0Wk1OvO14PkVFCCeL6alXH+ev01e/VoByQDTe1c=; b=HI1l+roMyUHt9ZOkqyHL0m9XymhoLAg+xJMhRp/kZd75nh25ljZNDSs641+C2ibFZX 6nU6VTFYjhLrB9fdK8Doa03h2f7+X3K/U0xQ6ZFEzNrFWPiYkiGrUyR+TCRvBGxfAmg5 s1YZ3jxHsg80pmlv50o+ADigIgFe214L5MYlHJCjwZzFxnh+b+KRvwfapb1jlG2b1m68 ecI7n7gi4vcAPHoGtkSHnEIRRp6c/3bdPZR2XuwYyKc6ZOXV5kz9shHmey2JENh0s/fr eTNIUnLRmggj2U+6rCoPfJ6NtOtmW3jORYs9Gulv/iVVwMwMqHxPl88yG3pK5HkFy4H9 Ah8Q==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=x-gm-message-state:mime-version:in-reply-to:references:from:date :message-id:subject:to:cc:content-type:content-transfer-encoding; bh=MSqa0Wk1OvO14PkVFCCeL6alXH+ev01e/VoByQDTe1c=; b=lURL9DJ3MjNww7r4o3VNNnuXShbUpqcwgJ8C5nMbkbQbaz2Lly61cpLCWW5yrxreR1 5KXalzMkOolppAv+U/evrAKDrosg4UE/2EDBGttxSo+0lfEsRtdVruBZuCKpsu15rmdl hwz0WQkkBqkIG68qeGllPPWHOK8N2uDZxblH9ZxCNMIk3tloqX6okTuKxmdEqPMKT5R0 zmMA3C11RKfnVYVrk3CeA893xkzu88TGUdnze7xG/WkhywmSbrKCCMHMzNa/wdaVJFXT nb+gzf1c7exdbxWZ5+jQHWqzdRTbng7Fgz/40OaToSGGJUSiXm1TlApIY6gQedFOUYEt E69Q==
X-Gm-Message-State: ALoCoQkHKBgLmsatWeFsDlTyMKMo2ffaH7UhAvr1wucHkqnarhFL53q2prLjoKRCNcJdrLr0NeKx
X-Received: by 10.194.78.210 with SMTP id d18mr74961866wjx.34.1438179110357; Wed, 29 Jul 2015 07:11:50 -0700 (PDT)
MIME-Version: 1.0
Received: by 10.28.138.203 with HTTP; Wed, 29 Jul 2015 07:11:30 -0700 (PDT)
In-Reply-To: <DAF1C040-9792-4846-B139-56EC94EC2076@nominum.com>
References: <alpine.DEB.2.02.1507230910190.11810@uplift.swm.pp.se> <4797B33E-9851-427E-8710-84122AFD0FFA@cisco.com> <m1ZKMsw-0000CCC@stereo.hq.phicoh.net> <DAF1C040-9792-4846-B139-56EC94EC2076@nominum.com>
From: Erik Kline <ek@google.com>
Date: Wed, 29 Jul 2015 23:11:30 +0900
Message-ID: <CAAedzxpzjPWbjfchhJpTUKZ2V-OEJAE6xxQ3H1-UYQsi79QmTg@mail.gmail.com>
To: Ted Lemon <ted.lemon@nominum.com>
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable
Archived-At: <http://mailarchive.ietf.org/arch/msg/v6ops/R5GRdZiW4e1G_H2B4xgyH-ziVds>
Cc: "v6ops@ietf.org" <v6ops@ietf.org>
Subject: Re: [v6ops] NAT64/DNS64 and DNSSEC
X-BeenThere: v6ops@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: v6ops discussion list <v6ops.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/v6ops>, <mailto:v6ops-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/v6ops/>
List-Post: <mailto:v6ops@ietf.org>
List-Help: <mailto:v6ops-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/v6ops>, <mailto:v6ops-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 29 Jul 2015 14:11:53 -0000

On 29 July 2015 at 23:01, Ted Lemon <ted.lemon@nominum.com> wrote:
> On Jul 29, 2015, at 4:38 AM, Philip Homburg <pch-v6ops-3@u-1.phicoh.com>
> wrote:
>
> I don't like it either. But there seems to be a vocal group of operators who
> like it. Not a lot of opposition and now Apple seems to like it as well.
>
>
> I don’t really know what all the hate is for NAT64.   It does a great job of
> letting me run a v6only network whilst still communicating with v4 services
> on the Internet.  Maybe it’s not everybody’s cup of tea, but it’s a pretty
> nice solution, and I agree that making it work with DNSSEC ought to be a
> priority.

The suckiness, such as it is, is a feature, not a bug (vis a vis
Cameron's earlier comment).