Re: Empty AA=0 AD=1 answers to AAAA queries: your thoughts pls

Mark Andrews <[email protected]> Sun, 21 Dec 2014 01:25:06 +1100
Newsgroups gmane.ietf.dnsext
Message-ID <[email protected]>
In message <[email protected]>, bert hubert writes:
> Hi everybody,
> 
> I have a question if I am right in concluding something is a protocol
> violation, and if we should reward it by papering it over or (finally)
> concluding that enough is enough.

I've been thinking for a long time that enough is enough.  Named tried
to reject all non referral "aa=0" from supposedly authoritative servers
a while back and we had to reverse the change.  While pandora.tv has
fixed the aa=0 issue they still return malformed answers.

What we really need is for TLD operators to audit all the delegated
servers and inform their owners when they see a broken one.  They
are the ones with the lists of authoritative servers and the contact
information.

See draft-andrews-dns-no-response-issue.

> A few weeks ago we posted this
> http://mailman.powerdns.com/pipermail/pdns-users/2014-December/011004.html
> about Microsoft Azure nameservers sending empty answers (AD=1 no less) to
> AAAA queries. Microsoft has indicated they'll get to addressing this early
> 2015, by the way (thanks Mehmet).
> 
> However, we're now seeing more and more of this, for example from the most
> popular news site in the Netherlands nu.nl: 
> 
> $ dig +trace -t aaaa nu-nl.gslb.sanomaservices.nl.
> 
> Which ends on:
> 
> $ dig -t aaaa nu-nl.gslb.sanomaservices.nl. @62.69.175.251
> ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 58444
> ;; flags: qr rd ad; QUERY: 1, ANSWER: 0, AUTHORITY: 0, ADDITIONAL: 1
> ;; OPT PSEUDOSECTION:
> ; EDNS: version: 0, flags:; udp: 1280
> ;; QUESTION SECTION:
> ;nu-nl.gslb.sanomaservices.nl.	IN	AAAA
> 
> Note that this is the same pattern as Microsoft Azure. But this empty AA=0
> answer leads PowerDNS to:
> 
>  nu-nl.gslb.sanomaservices.nl.: Trying IP 62.69.175.251:53 1, asking 'nu-nl.g
> slb.sanomaservices.nl.|AAAA'
>  nu-nl.gslb.sanomaservices.nl.: Got 0 answers from gslb2.sanomaservices.nl. (
> 62.69.175.251), rcode=0 (No Error), aa=0, in 6ms
>  nu-nl.gslb.sanomaservices.nl.: determining status after receiving this packe
> t
>  nu-nl.gslb.sanomaservices.nl.: status=NS gslb2.sanomaservices.nl. (62.69.175
> .251) is lame for 'gslb.sanomaservices.nl.', trying sibling IP or NS
>  nu-nl.gslb.sanomaservices.nl.: Failed to resolve via any of the 2 offered NS
>  at level 'gslb.sanomaservices.nl.'
>  nu-nl.gslb.sanomaservices.nl.: failed (res=-1)
> 
> And this means we send out a SERVFAIL to our client, since all servers are
> 'lame'.  This makes some programs very unhappy.
> 
> We are (as is any resolver implementor) receiving pressure not to do this,
> and to paper over this behaviour. There is a workaround available in the URL
> above.
> 
> We think the time has to come to say 'no, if you run a non-confirming
> implementation, you deserve all the pain you get'. 
> 
> But before we make a stand, what do you think? Should we accept empty AA=0
> AD=1 answers as "NO ERROR"? 

Personally I would like to take a stand.  Whether we can convince others
is another matter.
 
> Please let us know.
> 
> 	Bert
> 
> _______________________________________________
> dnsext mailing list
> [email protected]
> https://www.ietf.org/mailman/listinfo/dnsext
-- 
Mark Andrews, ISC
1 Seymour St., Dundas Valley, NSW 2117, Australia
PHONE: +61 2 9871 4742                 INTERNET: [email protected]

_______________________________________________
dnsext mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/dnsext