Re: TTL on DS records

Ralf Weber <[email protected]> Sat, 21 Feb 2015 20:19:34 +0100
Newsgroups gmane.ietf.dnsext
Message-ID <[email protected]_W_724V_01011601_00_009>
Moin!

On Sat, Feb 21, 2015 at 07:21:04AM -0500, Andrew Sullivan wrote:
> On Sat, Feb 21, 2015 at 12:15:29PM +0100, Patrik F=E4ltstr=F6m wrote:
> > =

> > My personal view is that the TTL for the DS should be really short.
> =

> This would be yet another reason for people not to turn on validation,
> because validating will become an excellent way to increase latency in
> page loading.  It seems to me that you want to defend against one
> problem (lousy operator) by creating a new one (poor caching).  I'm
> not convinced that's an excellent trade off.
I don't see how this will increase latency of page loading. Most
recursive resolvers these day do pre fetching for often used records
and if the record isn't in the cache the difference in latency comes =

from validation anyway.

I think we need to move away from TTLs in the days or even week range
to TTLs that are in the hours range. I think one hour is a good TTL
for DNSSEC stuff. If your domain isn't asked once an hour in a big
providers network chances are it would have fallen out of the cache
becuse of LRU anyway during that time frame.

So long
-Ralf

_______________________________________________
dnsext mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/dnsext