Re: Naked domain resolution with DNSSEC
Kumar Ashutosh <[email protected]> Wed, 23 Oct 2013 19:19:19 +0000
| Newsgroups | gmane.ietf.dnsext |
|---|---|
| Message-ID | <E66B38BB793BAF439EF374F3E7EBEE464B620A63@SINEX14MBXC415.southpacific.corp.microsoft.com> |
Thanks Dave! -----Original Message----- From: Dave Lawrence [mailto:[email protected]] Sent: Thursday, October 24, 2013 12:33 AM To: Kumar Ashutosh Cc: Jim Reid; Thirunadha Reddy; [email protected] Group; Sourav Sain Subject: RE: [dnsext] Naked domain resolution with DNSSEC Kumar Ashutosh writes: > I agree on CNAME behaviour. My concern here is what option does the > customer have in case he needs contoso.com and www.contoso.com both to > be redirected to say contoso.dnsprovider.com The customer in this case needs special handling by the authoritative server to hand out address records at the apex instead. Several DNS providers handle this in their own software; for example, Akamai has a feature called "toplevel name redirection" to do it. DNS Made Easy has what they call an "ANAME record", described at http://www.dnsmadeeasy.com/services/aname-records/. It isn't really an IETF/IANA acknowledged DNS record, but rather just the way they describe how to configure it into their system. This is a fundamental limitation of the DNS protocol. To achieve the desired effect you must use some mechanism that is outside the scope of current DNS standards documents. _______________________________________________ dnsext mailing list [email protected] https://www.ietf.org/mailman/listinfo/dnsext