Re: The state of DNS support, was Deprecating SPF

Hadriel Kaplan <[email protected]>
Newsgroups gmane.ietf.dnsext
Message-ID <[email protected]>
On Aug 27, 2013, at 11:23 AM, Mark Andrews <[email protected]> wrote:

> There are DNS servers that completely support arbitary types.  And
> have for over a decade.  Before that they could resolve and cache
> arbitary types and have done so for over 20 years.  About the only
> one that doesn't is that shipped by Microsoft.
> 
> There are DNS resolvers that support arbitary types and have been
> able to for over 20 years.  This is basic RFC 1034 functionality.
> Unfortunately Microsoft failed to read that part of RFC 1034 or
> failed to understand it when they were developing their resolver
> code.
> 
> Most firewalls don't care diddly squat about DNS record types.  For
> those that do blocking unknown types in firewalls does diddly squat
> for security and just cause problems for everyone.  Just turn the
> DNS checking off.
> 
> NAT (carrier grade or otherwise) don't care about DNS message
> content. 
> Then there are provisioning systems which haven't been upgraded
> since Noah was a boy and you don't have to use anyway.

Actually, I know of at least one CGN that does.

But it doesn't really matter...  I think you're missing the point.  The point isn't that NONE support unknown RRs, the point is that SOME do not.  Of course a lot of things do support unknown RR types. 

So if you're a developer of some new thing, and you want everyone, everywhere, to be able to use your new thing, would you choose to use a new RR knowing some of your potential users can't use that?  Or would you choose to use something you know works for everyone everywhere?

It's a very hard thing to ignore a potential part of your target user base, or hope to force them to replace equipment or change DNS registries just to use your new thing.  It's a barrier to adoption most developers would want to avoid, I would think.

-hadriel

_______________________________________________
dnsext mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/dnsext
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.