Re: Fwd: New Version Notification for draft-wouters-edns-tcp-chain-query-00.txt
Jelte Jansen <[email protected]>
| Newsgroups | gmane.ietf.dnsext |
|---|---|
| Message-ID | <[email protected]> |
On 09/11/2013 03:15 AM, Paul Wouters wrote: > > Abstract: > This document defines an EDNS0 extension that can be used by a DNSSEC > enabled Recursive Nameserver configured as a forwarder to send a > single query over TCP requesting to receive a complete validation > path along with the regular query answer. Additionally, use of this > option is considered a request to keep the TCP connection open to > serve additional DNS requests. Use of this option significantly > reduces DNS latency for hosts deploying DNSSEC. > Want! Some thoughts after a very quick read: - It should probably mention what to do with CNAMES (my guess would be return data until cname and let client requery with chain option for that) - Depending on above, I don't think *infinite* chains are possible (though prohibitively long ones are) - Should there be a considerations section about timeouts? BTW, I have a sneaking suspicion there also might be a bit of trickery regarding keys of multiple where some chains are valid and some are not, but I haven't got a specific example in my head yet. Jelte _______________________________________________ dnsext mailing list [email protected] https://www.ietf.org/mailman/listinfo/dnsext