Re: TTL on DS records
Ralf Weber <[email protected]> Sat, 21 Feb 2015 20:19:34 +0100
| Newsgroups | gmane.ietf.dnsext |
|---|---|
| Message-ID | <[email protected]_W_724V_01011601_00_009> |
Moin! On Sat, Feb 21, 2015 at 07:21:04AM -0500, Andrew Sullivan wrote: > On Sat, Feb 21, 2015 at 12:15:29PM +0100, Patrik F=E4ltstr=F6m wrote: > > = > > My personal view is that the TTL for the DS should be really short. > = > This would be yet another reason for people not to turn on validation, > because validating will become an excellent way to increase latency in > page loading. It seems to me that you want to defend against one > problem (lousy operator) by creating a new one (poor caching). I'm > not convinced that's an excellent trade off. I don't see how this will increase latency of page loading. Most recursive resolvers these day do pre fetching for often used records and if the record isn't in the cache the difference in latency comes = from validation anyway. I think we need to move away from TTLs in the days or even week range to TTLs that are in the hours range. I think one hour is a good TTL for DNSSEC stuff. If your domain isn't asked once an hour in a big providers network chances are it would have fallen out of the cache becuse of LRU anyway during that time frame. So long -Ralf _______________________________________________ dnsext mailing list [email protected] https://www.ietf.org/mailman/listinfo/dnsext