Re: The state of DNS support, was Deprecating SPF

Måns Nilsson <[email protected]>
Newsgroups gmane.ietf.dnsext
Message-ID <[email protected]>
Subject: Re: [dnsext] The state of DNS support, was Deprecating SPF Date: Tue, Aug 27, 2013 at 07:44:21AM -0700 Quoting Nicholas Weaver ([email protected]):
> 
> On Aug 27, 2013, at 7:25 AM, Hadriel Kaplan <[email protected]> wrote:
> 
> > But from reading the problems SPF listed in RFC 6686 and the emails from SPFBIS folks, I don't think that would solve the problem, even if by some miracle all DNS servers on the planet supported the new RRs.  There're just too many other DNS-related-things involved. (DNS servers and registries, and their provisioning interfaces, and DNS resolvers/caches, firewalls, CGN middleboxes, client libraries and their APIs...)
> 
> Fortunately, for MOST such boxes, they do actually handle unknown resource records right (we've been testing that with Netalyzr for almost forever, with type 169 on transport, and 1169 on probes to configured recursive resolvers).  Namely because the protocol is actually designed right in that respect: its actually easier to handle ALL types in a generic manner after special casing the FEW types that allow name compression.
> 
> Thus it really is that the major problem is provisioning, not transport, of unknown DNS types.

This is indeed interesting data that "complicates" the IMNSHO
sweeping statements of 6686. The provisioning problem remains, but the
infrastructure is not as broken as stated.

Or? 

-- 
Måns Nilsson     primary/secondary/besserwisser/machina
MN-1334-RIPE                             +46 705 989668
... I think I'd better go back to my DESK and toy with a few common
MISAPPREHENSIONS ...

_______________________________________________
dnsext mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/dnsext
signature.asc (application/pgp-signature, 198 B)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.10 (GNU/Linux)

iEYEARECAAYFAlIcwXIACgkQ02/pMZDM1cW5awCgqBaqSBobkEQtuufB7g3jKxl7
JMAAnjG8bQgifRWmQAZ3XYCUHzxx1mO3
=vshl
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.