Re: TTL on DS records
Patrik Wallström <[email protected]> Sat, 21 Feb 2015 11:50:39 +0100
| Newsgroups | gmane.ietf.dnsext |
|---|---|
| Message-ID | <[email protected]> |
This is an OpenPGP/MIME signed message (RFC 4880 and 3156) --===============7089629378054933506== Content-Type: multipart/signed; micalg=pgp-sha1; protocol="application/pgp-signature"; boundary="AAM67q2HJe5oeFE5QG2Ae6xpwIfiRKWD1" This is an OpenPGP/MIME signed message (RFC 4880 and 3156) --AAM67q2HJe5oeFE5QG2Ae6xpwIfiRKWD1 Content-Type: text/plain; charset=windows-1252 Content-Transfer-Encoding: quoted-printable On 21/02/15 02:19, Wessels, Duane wrote: > Section 5 of RFC 4034 says: > > The DS RR has no special TTL requirements. > > While RFC 4035 Section 2.4 says: > > The TTL of a DS RRset SHOULD match the TTL of the delegating NS RRse= t > > Due the "SHOULD" I'm not sure this is worthy of an errata, but seems ra= ther unfortunate. > > Apologies if this is a previously known issue. Several TLD operators have a lower TTL on the DS. The reason is to help the registrant to recover from a signature failure and be fast to remove the DS. I think this is one of the reasons to why there is a SHOULD there= =2E --AAM67q2HJe5oeFE5QG2Ae6xpwIfiRKWD1 Content-Type: application/pgp-signature; name="signature.asc" Content-Description: OpenPGP digital signature Content-Disposition: attachment; filename="signature.asc" -----BEGIN PGP SIGNATURE----- Version: GnuPG/MacGPG2 v2 Comment: GPGTools - http://gpgtools.org iQIcBAEBAgAGBQJU6GMDAAoJENv/4te3Ykny/JcP/1EqybmYWFLRK+uzuCRWJux4 ysS3qra1W6d7TimfCK1cfbMGHtlc9YVtiAw3n1g08ZgG9ZR9a1qXXVIpMvcb8F00 6d2LhvfyYC+03D4SPe05IihR+dKL5MVFH0XQTWot60ed+b+YN4Qj7PFJwnZPpnpJ 8dGn+r6AHA+MPlQzggfZcGnqqtt2MJ3BbT47R1RiGy33J1chHmgjIMrLfWEgnBnS PT2sFt4cCWqQtqWbEXt7sIb6JrJRW4HdE4oS2rxTf+j+ONOeX8oBk1Tr6wKbCBUs xIzom7oisZOIufIFuh8Qyv5M0JG4WSFj60ck33M9kYrgeQ1gR8R2wSfBd0ORpTDC npf5/wL1Lh1ZaP/6qAKk6Ukj648GIur0V0L7aLckRqfjxhR0p7/KfCzOsIbE1hhz bf0mnB6Qu+JrhxUiXU+PMB/JVOUGz5WNc340SnOqyho9DxB3Ejaw23qcXCKdKNLH ed5V0hCY/U5JYy6XnhELSbAZu5jonzBqKulXV6+iCzpvcT3MSvul1YaCq7bKshCd r0MG4yFp55KxIyTSt5uhhYHIdzvaXf2P7czazZIa5IIPSdkpXgdhi/IC5UTkiEwB Z1vdSIu0Agl/tllE4ftTyFbJDZQz1DKPJj3m+nBpGo7EnYShcREkZvx+qs45CI55 lbWk2qVqj0oXlq/9kiT5 =Qoda -----END PGP SIGNATURE----- --AAM67q2HJe5oeFE5QG2Ae6xpwIfiRKWD1-- --===============7089629378054933506== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ dnsext mailing list [email protected] https://www.ietf.org/mailman/listinfo/dnsext --===============7089629378054933506==--