Re: enough is enough

Patrik Fältström <[email protected]> Mon, 22 Dec 2014 06:50:33 +0100
Newsgroups gmane.ietf.dnsext
Message-ID <[email protected]>
--===============0764213331092441494==
Content-Type: multipart/signed;
 boundary="Apple-Mail=_B709CCBC-BC83-4C5B-8CD8-1B12F0F34DBD";
 protocol="application/pgp-signature"; micalg=pgp-sha1


--Apple-Mail=_B709CCBC-BC83-4C5B-8CD8-1B12F0F34DBD
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain;
	charset=iso-8859-1


> On 21 dec 2014, at 15:33, bert hubert <[email protected]> =
wrote:
>=20
> On Sun, Dec 21, 2014 at 11:33:17AM +0100, Patrik F=E4ltstr=F6m wrote:
>>> The domain x.y.z fails to resolve using our software, and we have =
determined
>>> that this is because the software or hardware publishing the DNS =
details of
>>> x.y.z is not conforming to the DNS standards.
>> As Jim says, your idea is nice as it is, and there is nothing wrong =
with
>> the email -- but we have no idea what so ever where to send it.
>=20
> Actually, as the authors of a resolver, we know exactly where to send =
it. To
> the people telling me I need to fix my resolver so it works with =
broken
> domain X.

Ok, good. That is exactly what I claim is the most effective way of =
solving the issue.

> And in turn, we've found that (together with resolver operators) we =
can
> quickly find out what broken hardware or software is behind the issue =
-
> Citrix Netscalers this time round. It helps if large operators (people =
with
> tens of millions of customers) tell them they need to clean up their =
act.

Yes.

> The REAL issue right now is that we can't resist fixing a broken =
domain
> "because it works with Google/Unbound/Bind/Microsoft, so you must fix =
it".
>=20
> What is needed is a pact that none of us will respect that argument on =
its
> own if a domain actually should be broken.
>=20
>> The best path forward is I think still for you to publish clear and =
crisp
>> information like this on your web page so that it is found when =
searching
>> for help with Google and other search engines.
>>=20
>> I.e. as long as no one have any issues with the brokenness, it will =
not be fixed.
>=20
> Exactly. It should actually break therefore. If you own dodgy =
equipment or
> use bad software, your domain should receive lots of reports of =
brokenness.
>=20
>> If not even TLDs are hosted correctly, and registry policies are such =
that
>> it encourages broken DNS configurations, I feel there is not much The
>> Protocol Police can do about it.
>=20
> I'm afraid this is true. But if all big implementation decide to no =
longer
> play the game, the (mostly) load balancer implementations will have to =
clean
> up their act.
>=20
> I also note that quite a lot of problems are AAAA related. This in =
itself is
> an impediment to IPv6 adoption!

Yes.

   Patrik


--Apple-Mail=_B709CCBC-BC83-4C5B-8CD8-1B12F0F34DBD
Content-Transfer-Encoding: 7bit
Content-Disposition: attachment;
	filename=signature.asc
Content-Type: application/pgp-signature;
	name=signature.asc
Content-Description: Message signed with OpenPGP using GPGMail

-----BEGIN PGP SIGNATURE-----
Comment: GPGTools - http://gpgtools.org

iD8DBQFUl7EqrMabGguI180RAnaXAKCR+u4RdmSLH6bW3pGyIpGFazjl7gCgichW
WEY57V9anJBSY37n2EAtiVc=
=Q01z
-----END PGP SIGNATURE-----

--Apple-Mail=_B709CCBC-BC83-4C5B-8CD8-1B12F0F34DBD--


--===============0764213331092441494==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
dnsext mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/dnsext

--===============0764213331092441494==--