Re: (BNAME) Naked domain resolution with DNSSEC

"Jiankang Yao" <[email protected]> Sun, 27 Oct 2013 10:23:08 +0800
Newsgroups gmane.ietf.dnsext
Message-ID <[email protected]>
I think that BNAME is compatible with DNSSEC. If you say BNAME is not compatible with DNSSEC, I think that it is due to protocol overhead.
 I suggest the following upadting to BNAME to reduce the protocol overhead:
  
  
If the query is a DNSSEC query, the BNAME enabled resolvers MUST set the UB (understand BNAME) bit in the query. The server receiving the UB bit MUST not issue synthesized CNAMEs or DNAME. Servers copy the UB bit to the response, and should delete the synthesized CNAMEs and DNAME from the answer if there has one. If the query is the DNSSEC query but the UB bit is not set, the server should follow the rules below:
 
a. If the owner name of the BNAME is same with the name queried, when preparing a response, a DNSSEC enabled server performing a BNAME substitution will not include the relevant BNAME  RR and its RRSIG RR in the answer section unless the type queried is BNAME . A CNAME RR with TTL=0 and its signed record will be included in the answer section unless the type queried is BNAME .
 
 b. If the owner name of the BNAME is the suffix of the name queried but not identical with the suffix, when preparing a response, a server performing a BNAME substitution will in all cases include the relevant BNAME RR in the answer section. A DNAME RR synthesized with TTL=0 and its signed DNAME RR are included in the answer section. This will help the client to reach the correct DNS data.

   
  
 Jiankang Yao

 

 ------------------ Original ------------------
  From:  "Andrew Sullivan";<[email protected]>;
 Date:  Fri, Oct 25, 2013 05:36 PM
 To:  "Jiankang Yao"<[email protected]>; 
 Cc:  "Dave Lawrence"<[email protected]>; "Kumar Ashutosh"<[email protected]>; "Thirunadha Reddy"<[email protected]>; "[email protected] Group"<[email protected]>; "Sourav Sain"<[email protected]>; 
 Subject:  Re: [dnsext] Naked domain resolution with DNSSEC

 

On Fri, Oct 25, 2013 at 05:25:48PM +0800, Jiankang Yao wrote:
> 
> BNAME, which directs both itself and its children, may solve it. the draft about BNAME was discussed 3 years ago.

> _______________________________________________

Yes, and if it were compatible with DNSSEC, perhaps people would have
pursued it.  But it won't work with DNSSEC.

Best,

A

-- 
Andrew Sullivan
[email protected]

_______________________________________________
dnsext mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/dnsext