Re: Empty AA=0 AD=1 answers to AAAA queries: your thoughts pls
Mark Andrews <[email protected]> Sun, 21 Dec 2014 01:25:06 +1100
| Newsgroups | gmane.ietf.dnsext |
|---|---|
| Message-ID | <[email protected]> |
In message <[email protected]>, bert hubert writes: > Hi everybody, > > I have a question if I am right in concluding something is a protocol > violation, and if we should reward it by papering it over or (finally) > concluding that enough is enough. I've been thinking for a long time that enough is enough. Named tried to reject all non referral "aa=0" from supposedly authoritative servers a while back and we had to reverse the change. While pandora.tv has fixed the aa=0 issue they still return malformed answers. What we really need is for TLD operators to audit all the delegated servers and inform their owners when they see a broken one. They are the ones with the lists of authoritative servers and the contact information. See draft-andrews-dns-no-response-issue. > A few weeks ago we posted this > http://mailman.powerdns.com/pipermail/pdns-users/2014-December/011004.html > about Microsoft Azure nameservers sending empty answers (AD=1 no less) to > AAAA queries. Microsoft has indicated they'll get to addressing this early > 2015, by the way (thanks Mehmet). > > However, we're now seeing more and more of this, for example from the most > popular news site in the Netherlands nu.nl: > > $ dig +trace -t aaaa nu-nl.gslb.sanomaservices.nl. > > Which ends on: > > $ dig -t aaaa nu-nl.gslb.sanomaservices.nl. @62.69.175.251 > ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 58444 > ;; flags: qr rd ad; QUERY: 1, ANSWER: 0, AUTHORITY: 0, ADDITIONAL: 1 > ;; OPT PSEUDOSECTION: > ; EDNS: version: 0, flags:; udp: 1280 > ;; QUESTION SECTION: > ;nu-nl.gslb.sanomaservices.nl. IN AAAA > > Note that this is the same pattern as Microsoft Azure. But this empty AA=0 > answer leads PowerDNS to: > > nu-nl.gslb.sanomaservices.nl.: Trying IP 62.69.175.251:53 1, asking 'nu-nl.g > slb.sanomaservices.nl.|AAAA' > nu-nl.gslb.sanomaservices.nl.: Got 0 answers from gslb2.sanomaservices.nl. ( > 62.69.175.251), rcode=0 (No Error), aa=0, in 6ms > nu-nl.gslb.sanomaservices.nl.: determining status after receiving this packe > t > nu-nl.gslb.sanomaservices.nl.: status=NS gslb2.sanomaservices.nl. (62.69.175 > .251) is lame for 'gslb.sanomaservices.nl.', trying sibling IP or NS > nu-nl.gslb.sanomaservices.nl.: Failed to resolve via any of the 2 offered NS > at level 'gslb.sanomaservices.nl.' > nu-nl.gslb.sanomaservices.nl.: failed (res=-1) > > And this means we send out a SERVFAIL to our client, since all servers are > 'lame'. This makes some programs very unhappy. > > We are (as is any resolver implementor) receiving pressure not to do this, > and to paper over this behaviour. There is a workaround available in the URL > above. > > We think the time has to come to say 'no, if you run a non-confirming > implementation, you deserve all the pain you get'. > > But before we make a stand, what do you think? Should we accept empty AA=0 > AD=1 answers as "NO ERROR"? Personally I would like to take a stand. Whether we can convince others is another matter. > Please let us know. > > Bert > > _______________________________________________ > dnsext mailing list > [email protected] > https://www.ietf.org/mailman/listinfo/dnsext -- Mark Andrews, ISC 1 Seymour St., Dundas Valley, NSW 2117, Australia PHONE: +61 2 9871 4742 INTERNET: [email protected] _______________________________________________ dnsext mailing list [email protected] https://www.ietf.org/mailman/listinfo/dnsext