enough is enough
bert hubert <[email protected]> Sun, 21 Dec 2014 10:44:54 +0100
| Newsgroups | gmane.ietf.dnsext |
|---|---|
| Message-ID | <[email protected]> |
On Sun, Dec 21, 2014 at 06:34:02AM +0100, Patrik Fältström wrote: > - ...policy in some registries require NS records for registrations of a domain (i.e. no difference between registration and delegation), there will be lame delegations To clarify, nothing like this is what I intended. Perhaps a prototype will help: "Dear domain operator, nameserver vendor, or load balancer purveyor, The domain x.y.z fails to resolve using our software, and we have determined that this is because the software or hardware publishing the DNS details of x.y.z is not conforming to the DNS standards. The violation is: Sending empty non-aa answers to AAAA queries The result is: our software generates a SERVFAIL response, confusing Microsoft Exchange. The product at fault is: Citrix Netscaler Please find further details attached to this message. While some other software or service is able to resolve your domain, we are not going to work around this issue. For years, all resolver vendors and service providers have papered over DNS protocol violations if one of the other big resolver implementations was able to resolve a domain. There is now a staggering amount of papering over in each nameserver implementation. As a DNS community, we have decided that enough is enough. We encourage you to contact the responsible vendor (see above). We are more than willing to talk to them if this helps them resolve the issue. Kind regards, PowerDNS, also on behalf of ISC, .., .. and .." This would then come with a website with further explanations, and perhaps even a registry of faults that has been decided we're not going to fix. I'm open to providing specific workaround configurations to individual operators if this helps them in the meantime, but they'll hate having to maintain all these workarounds, thus generating rising pressure on the vendors of broken equipment. Ideas? Bert > > - ...policy in some registries require NS records for registrations of a domain (i.e. no difference between registration and delegation), there will be proxy registrations and registrants that lie > > - ...data sent to a registry/registrar, regardless of data protection legislation, is available freely "on the net", there will be proxy registrations and registrants that lie > > - ...policy make it impossible to register domain names in some registries, there will be proxy registrations to circumvent the very same rules > > - ...there is no agreement on what data to send to registries for DNSSEC signed zones, it will be very hard to get lots of DNSSEC signed zones > > - ...policy in some registries that the registrant should contact them directly, registrars will lie to the registry during registration period so that they can give the registrant the service the registrant ask for > > I.e. the world out there is so messy that what you talk about is a light warm breeze... > > Just the notation of "the TLDs" to fix things is confusing to me. Does "the TLD" imply the registry, whoever is the administrative contact for the TLD in the IANA database, or the backend provider, or the technical contact or the one holding the whois record of the delegation the question is about, or... > > Patrik > _______________________________________________ dnsext mailing list [email protected] https://www.ietf.org/mailman/listinfo/dnsext