Re: Extending UPDATE to add/remove zones

Jay Daley <[email protected]>
Newsgroups gmane.ietf.dnsext
Message-ID <[email protected]>
Thanks to all those that replied.  I've summarised and responded to the points below:


1.  The restriction on FQDNs is too complex and there's no problem with provisioning multiple zones in multiple packets.

I agree and I'll change it so that only one master can be added per update.  I was indeed thinking about zone templating and that's not a DNS issue. 


2.  Clarify what the ZCLASS needs to be set to.

ZCLASS == ANY means delete,  ZCLASS != ANY means add.


3.  There is a substantial security risk here that needs to be addressed.

I agree.  Both zone transfer and dynamic updates have security added over the top through IP address restriction and/or TSIG and I think the same approach should be taken here of identifying the security issue and recommending over the top security but not requiring any.  It would also be useful to state that implementors must support TSIG for this and must not turn it on by default.


One more question - do we really need an EDNS option code as we could do it all by the ZTYPE + ZCLASS without breaking anything:

	ZTYPE == SOA and ZCLASS != ANY means update an existing zone
	ZTYPE == NS and ZCLASS != ANY means add an existing zone
	ZTYPE == NS and ZCLASS = ANY means delete an existing zone

Any thoughts?

Jay

-- 
Jay Daley
Chief Executive
.nz Registry Services (New Zealand Domain Name Registry Limited)
desk: +64 4 931 6977
mobile: +64 21 678840
linkedin: www.linkedin.com/in/jaydaley

_______________________________________________
dnsext mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/dnsext
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.