Re: Extending UPDATE to add/remove zones
Jay Daley <[email protected]>
| Newsgroups | gmane.ietf.dnsext |
|---|---|
| Message-ID | <[email protected]> |
Thanks to all those that replied. I've summarised and responded to the points below: 1. The restriction on FQDNs is too complex and there's no problem with provisioning multiple zones in multiple packets. I agree and I'll change it so that only one master can be added per update. I was indeed thinking about zone templating and that's not a DNS issue. 2. Clarify what the ZCLASS needs to be set to. ZCLASS == ANY means delete, ZCLASS != ANY means add. 3. There is a substantial security risk here that needs to be addressed. I agree. Both zone transfer and dynamic updates have security added over the top through IP address restriction and/or TSIG and I think the same approach should be taken here of identifying the security issue and recommending over the top security but not requiring any. It would also be useful to state that implementors must support TSIG for this and must not turn it on by default. One more question - do we really need an EDNS option code as we could do it all by the ZTYPE + ZCLASS without breaking anything: ZTYPE == SOA and ZCLASS != ANY means update an existing zone ZTYPE == NS and ZCLASS != ANY means add an existing zone ZTYPE == NS and ZCLASS = ANY means delete an existing zone Any thoughts? Jay -- Jay Daley Chief Executive .nz Registry Services (New Zealand Domain Name Registry Limited) desk: +64 4 931 6977 mobile: +64 21 678840 linkedin: www.linkedin.com/in/jaydaley _______________________________________________ dnsext mailing list [email protected] https://www.ietf.org/mailman/listinfo/dnsext