Re: Naked domain resolution with DNSSEC

Kumar Ashutosh <[email protected]> Wed, 23 Oct 2013 19:19:19 +0000
Newsgroups gmane.ietf.dnsext
Message-ID <E66B38BB793BAF439EF374F3E7EBEE464B620A63@SINEX14MBXC415.southpacific.corp.microsoft.com>
Thanks Dave!


-----Original Message-----
From: Dave Lawrence [mailto:[email protected]] 
Sent: Thursday, October 24, 2013 12:33 AM
To: Kumar Ashutosh
Cc: Jim Reid; Thirunadha Reddy; [email protected] Group; Sourav Sain
Subject: RE: [dnsext] Naked domain resolution with DNSSEC

Kumar Ashutosh writes:
> I agree on CNAME behaviour. My concern here is what option does the 
> customer have in case he needs contoso.com and www.contoso.com both to 
> be redirected to say contoso.dnsprovider.com

The customer in this case needs special handling by the authoritative server to hand out address records at the apex instead.  Several DNS providers handle this in their own software; for example, Akamai has a feature called "toplevel name redirection" to do it.  DNS Made Easy has what they call an "ANAME record", described at http://www.dnsmadeeasy.com/services/aname-records/.  It isn't really an IETF/IANA acknowledged DNS record, but rather just the way they describe how to configure it into their system.

This is a fundamental limitation of the DNS protocol.  To achieve the desired effect you must use some mechanism that is outside the scope of current DNS standards documents.


_______________________________________________
dnsext mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/dnsext