Re: The state of DNS support, was Deprecating SPF
Hadriel Kaplan <[email protected]>
| Newsgroups | gmane.ietf.dnsext |
|---|---|
| Message-ID | <[email protected]> |
On Aug 27, 2013, at 11:23 AM, Mark Andrews <[email protected]> wrote: > There are DNS servers that completely support arbitary types. And > have for over a decade. Before that they could resolve and cache > arbitary types and have done so for over 20 years. About the only > one that doesn't is that shipped by Microsoft. > > There are DNS resolvers that support arbitary types and have been > able to for over 20 years. This is basic RFC 1034 functionality. > Unfortunately Microsoft failed to read that part of RFC 1034 or > failed to understand it when they were developing their resolver > code. > > Most firewalls don't care diddly squat about DNS record types. For > those that do blocking unknown types in firewalls does diddly squat > for security and just cause problems for everyone. Just turn the > DNS checking off. > > NAT (carrier grade or otherwise) don't care about DNS message > content. > Then there are provisioning systems which haven't been upgraded > since Noah was a boy and you don't have to use anyway. Actually, I know of at least one CGN that does. But it doesn't really matter... I think you're missing the point. The point isn't that NONE support unknown RRs, the point is that SOME do not. Of course a lot of things do support unknown RR types. So if you're a developer of some new thing, and you want everyone, everywhere, to be able to use your new thing, would you choose to use a new RR knowing some of your potential users can't use that? Or would you choose to use something you know works for everyone everywhere? It's a very hard thing to ignore a potential part of your target user base, or hope to force them to replace equipment or change DNS registries just to use your new thing. It's a barrier to adoption most developers would want to avoid, I would think. -hadriel _______________________________________________ dnsext mailing list [email protected] https://www.ietf.org/mailman/listinfo/dnsext